AliExpress has come under scrutiny after a developer discovered hidden browser scripts processing inaudible audio signals on its website.

The scripts reportedly use audio processing as part of a wider system for identifying visitors’ browsers and devices.

Developer Matthew Callaghan discovered the activity after noticing unusual behavior with his Bluetooth headphones. Music playing from his phone reportedly stopped whenever the AliExpress website remained open on his computer.

His headphones supported Bluetooth multipoint connections between his computer and smartphone. Closing the website restored playback from his phone immediately.

However, muting the website, Firefox browser, or Windows did not resolve the problem.

How the AliExpress Audio Processing Worked

Callaghan investigated the behavior and found no hidden video, advertisement, or standard audio file causing the issue. Instead, he identified two heavily obfuscated Alibaba scripts called collina.js and fireyejs.js.

According to his analysis, the scripts created active WebAudio processing contexts inside the browser. They generated a sawtooth waveform and measured how the browser and computer processed the signal.

The scripts then examined frequency information produced during that process.

Importantly, the final audio volume was reportedly set to zero. This meant users could not hear the generated sound.

However, the audio processing system remained connected to the computer’s audio output. That connection reportedly kept the computer’s audio session active.

On Callaghan’s setup, this prevented his Bluetooth headphones from switching normally back to his smartphone.

Fingerprinting Goes Beyond Audio

The audio test reportedly represents only one part of the browser fingerprinting process. The scripts were also found examining several other device and browser characteristics.

These included Canvas rendering, WebGL, screen dimensions, viewport size and device pixel ratio. Hardware concurrency and available device memory were also reportedly examined.

The system also checked supported media formats and WebRTC behavior. Other collected signals reportedly involved browser performance, plugins and user interactions.

Mouse activity, touch activity, scrolling and browser focus events were among the examined signals. Motion and orientation information could also form part of the process.

The scripts reportedly looked for indicators commonly associated with browser automation. Combining these characteristics can create a detailed browser or device fingerprint.

Such techniques can distinguish devices without depending entirely on traditional tracking cookies.

Scripts May Be Linked to Anti-Fraud Systems

The scripts appear connected to Alibaba’s AWSC security and anti-abuse infrastructure. This suggests the fingerprinting technology could be designed to help detect fraud or automated activity.

However, Callaghan raised concerns about when the fingerprinting process takes place. According to his findings, it runs on the general AliExpress homepage.

Users do not need to log in or begin making a payment before the process starts. The findings have therefore raised questions about transparency and the extent of device fingerprinting on major websites.

Browser fingerprinting itself can have legitimate security applications, including fraud and bot detection. However, its use can also create privacy concerns when visitors are unaware of the information being collected.

In other news read more about: New Cyber Fraud Targets WhatsApp Users With Fake Parcel Calls

The findings regarding AliExpress are based on Callaghan’s technical investigation of the website’s browser scripts.