MB Bluejuice
Security

Sudden server load: a cryptominer on your machine

The CPU is maxed out, the site is slow and traffic has not changed. How to spot a foreign process.

· updated 2026-10-07

When the CPU runs flat out while visitor numbers match last month, the cause is rarely “a heavy plugin”.

Signs

  • Load stays evenly high at night, when there are almost no visitors.
  • The process list shows an executable from /tmp or /dev/shm.
  • A process named like a system one, but with a letter changed.
  • Outbound connections to unusual ports (3333, 5555, 7777, 14444).
  • A cron job that downloads and runs a script every few minutes.

A quick check

top shows the process creating the load, and ls -l /proc/<PID>/exe reveals the real file behind it. ss -tupn lists outbound connections. Check cron jobs for every user, not just root.

Why killing the process is not enough

A miner almost always installs at least two persistence mechanisms: a cron job plus a systemd unit or an entry in .bashrc. Kill the process and it returns within minutes.

More importantly: if someone could run their own code on your server, mining is only one possible outcome. How it got there and what else it reached both need investigation — see incident response, and for properly configured servers, webhostas.com.

Next

Related articles

Need help with your website?

We will review your situation and tell you what to do first.