Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious sites use JavaScript to build malware in browser memory

0
Medium
Published: 07/25/2026 (07/25/2026, 15:21:09 UTC)
Source: Bleeping Computer

Description

A large malvertising campaign uses fake Solana, Luno, and TradingView websites with malicious JavaScript that assembles malware directly in browser memory. The attack uses service workers and shared workers to build a unique malware executable locally, avoiding transmission of a complete file over the network. This technique helps evade static detection and complicates analysis. The campaign targets retail traders and crypto investors primarily in Asia Pacific and Latin America. The malware reportedly can intercept network traffic, steal credentials and cryptocurrency wallet data, record keystrokes, take screenshots, and maintain persistence. Users are advised to download financial software only from official sources and verify digital signatures.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/25/2026, 15:22:17 UTC

Technical Analysis

This malvertising campaign, active since late 2024, leverages fake cryptocurrency and trading websites that use JavaScript to assemble malware in the browser's memory. The attack registers service and shared workers to incrementally build a malicious executable from remote components and local assembly templates, resulting in a unique file hash per session to bypass static detection. The final executable is downloaded via a same-origin path, making detection more difficult. The campaign filters targets to focus on retail traders and crypto investors and operates in 12 countries with 25 languages, mainly in Asia Pacific and Latin America. Analysis links this campaign to the SourTrade operation, which previously used the StreamSaver project for payload delivery. The malware capabilities include network traffic interception, credential theft, keylogging, screenshot capture, cryptocurrency wallet theft, and persistence.

Potential Impact

The malware can intercept all user network traffic, collect cookies and passwords, record keystrokes, take screenshots, steal cryptocurrency wallet data, and establish long-term persistence on infected systems. This poses significant risks to targeted retail traders and crypto investors, potentially leading to credential compromise, financial theft, and ongoing system compromise. The unique assembly method reduces detection likelihood and complicates forensic analysis.

Mitigation Recommendations

No official patch or fix is applicable as this is a web-based malvertising campaign. Users should avoid downloading financial or cryptocurrency-related applications from social media ads or sponsored search results. It is recommended to obtain executable files only from official company websites and verify the digital signature and publisher before execution. Security teams should be aware of this delivery technique but no direct remediation is provided by vendors. Patch status is not yet confirmed — check vendor advisories for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.bleepingcomputer.com/news/security/malicious-sites-use-javascript-to-build-malware-in-browser-memory/","fetched":true,"fetchedAt":"2026-07-25T15:22:07.513Z","wordCount":863}

Threat ID: 6a64d49f9c2644c7f886b7f7

Added to database: 07/25/2026, 15:22:07 UTC

Last enriched: 07/25/2026, 15:22:17 UTC

Last updated: 07/26/2026, 01:53:08 UTC

Views: 17

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses