AliExpress has been caught using hidden WebAudio processing in the background, even when you’re not playing any audio.
An investigation found that AliExpress loads Alibaba security scripts that create audio contexts and process a generated waveform.
This can contribute to browser and device fingerprinting, alongside techniques such as Canvas and WebGL fingerprinting.
Brave says it blocks these audio fingerprinting attempts by default, preventing the AliExpress scripts from collecting this data.
The investigation also found that the hidden audio processing could interfere with Bluetooth multipoint headphones by keeping them connected to a computer.
🚨SHOCKING: AliExpress was secretly tracking users through their computer's audio system without consent.
A developer only discovered it because his Bluetooth headphones stopped switching between devices while browsing the site.
He found hidden scripts playing an inaudible sound and measuring how each device processed it differently, creating a fingerprint that cannot be cleared like a cookie.
The scripts also collected screen data, device memory, mouse behavior, and network signals, all sent back to Alibaba's servers.
Muting the tab does not stop it. Firefox and Brave block it by default. Chrome does not.
🦔A developer found that loading the AliExpress homepage triggers hidden scripts that use your browser's audio system to fingerprint your computer. The scripts generate a silent waveform, run it through your audio hardware, and measure the output to create a unique identifier for your machine.
No sound plays, no permission is asked, and it runs even when the page is sitting idle. The scripts were identified as part of Alibaba's browser security tooling. Firefox lets you disable it. Brave blocks it by default. Most people have no idea it's happening.
My Take
A guy found this because his Bluetooth headphones started acting weird when he opened AliExpress. He dug into it, found hidden scripts running silent audio through his browser to fingerprint his machine, and realized the site had been doing it on every page load without any indication. If his headphones hadn't glitched he never would have looked, and no regulator or audit caught it either. The EFF has a free tool called Cover Your Tracks that shows how trackable your browser is, and based on everything going on right now with data collection I'd run it.
Hedgie🤗
The EU fines Alibaba's online marketplace AliExpress €550M for failing to do enough to prevent the sale of illegal products, the largest DSA fine to date (@bmoens / Financial Times)
(Visit Techmeme dot com for the link and full context!)
Beijing accused the EU and France of discriminatory treatment after AliExpress was fined €550 million and Paris approved stricter rules for ultra-fast-fashion companies. The clash highlights widening tensions over Chinese e-commerce in Europe
If you ever bought one of these $30 HY300 or similar projectors from Temu/Aliexpress, well, it's compromised with MALWARE ‼️
Somebody just used Claude Code to analyze and reverse engineer what it actually phones home.
TL;DR - your home is being used as a residential proxy and sold via a third party Chinese service.
Author states: "Anyone who paid Kookeey for proxy access could route their traffic through my IP"
Is the risk of getting DPRK agents or CP peddlers on your home WiFi worth the savings?