Malicious sites use JavaScript to build malware in browser memory
A large malvertising campaign uses fake Solana, Luno, and TradingView websites with malicious JavaScript that assembles malware directly in browser memory. The attack uses service workers and shared workers to build a unique malware executable locally, avoiding transmission of a complete file over the network. This technique helps evade static detection and complicates analysis. The campaign targets retail traders and crypto investors primarily in Asia Pacific and Latin America. The malware reportedly can intercept network traffic, steal credentials and cryptocurrency wallet data, record keystrokes, take screenshots, and maintain persistence. Users are advised to download financial software only from official sources and verify digital signatures.
AI Analysis
Technical Summary
This malvertising campaign, active since late 2024, leverages fake cryptocurrency and trading websites that use JavaScript to assemble malware in the browser's memory. The attack registers service and shared workers to incrementally build a malicious executable from remote components and local assembly templates, resulting in a unique file hash per session to bypass static detection. The final executable is downloaded via a same-origin path, making detection more difficult. The campaign filters targets to focus on retail traders and crypto investors and operates in 12 countries with 25 languages, mainly in Asia Pacific and Latin America. Analysis links this campaign to the SourTrade operation, which previously used the StreamSaver project for payload delivery. The malware capabilities include network traffic interception, credential theft, keylogging, screenshot capture, cryptocurrency wallet theft, and persistence.
Potential Impact
The malware can intercept all user network traffic, collect cookies and passwords, record keystrokes, take screenshots, steal cryptocurrency wallet data, and establish long-term persistence on infected systems. This poses significant risks to targeted retail traders and crypto investors, potentially leading to credential compromise, financial theft, and ongoing system compromise. The unique assembly method reduces detection likelihood and complicates forensic analysis.
Mitigation Recommendations
No official patch or fix is applicable as this is a web-based malvertising campaign. Users should avoid downloading financial or cryptocurrency-related applications from social media ads or sponsored search results. It is recommended to obtain executable files only from official company websites and verify the digital signature and publisher before execution. Security teams should be aware of this delivery technique but no direct remediation is provided by vendors. Patch status is not yet confirmed — check vendor advisories for updates.
Malicious sites use JavaScript to build malware in browser memory
Description
A large malvertising campaign uses fake Solana, Luno, and TradingView websites with malicious JavaScript that assembles malware directly in browser memory. The attack uses service workers and shared workers to build a unique malware executable locally, avoiding transmission of a complete file over the network. This technique helps evade static detection and complicates analysis. The campaign targets retail traders and crypto investors primarily in Asia Pacific and Latin America. The malware reportedly can intercept network traffic, steal credentials and cryptocurrency wallet data, record keystrokes, take screenshots, and maintain persistence. Users are advised to download financial software only from official sources and verify digital signatures.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This malvertising campaign, active since late 2024, leverages fake cryptocurrency and trading websites that use JavaScript to assemble malware in the browser's memory. The attack registers service and shared workers to incrementally build a malicious executable from remote components and local assembly templates, resulting in a unique file hash per session to bypass static detection. The final executable is downloaded via a same-origin path, making detection more difficult. The campaign filters targets to focus on retail traders and crypto investors and operates in 12 countries with 25 languages, mainly in Asia Pacific and Latin America. Analysis links this campaign to the SourTrade operation, which previously used the StreamSaver project for payload delivery. The malware capabilities include network traffic interception, credential theft, keylogging, screenshot capture, cryptocurrency wallet theft, and persistence.
Potential Impact
The malware can intercept all user network traffic, collect cookies and passwords, record keystrokes, take screenshots, steal cryptocurrency wallet data, and establish long-term persistence on infected systems. This poses significant risks to targeted retail traders and crypto investors, potentially leading to credential compromise, financial theft, and ongoing system compromise. The unique assembly method reduces detection likelihood and complicates forensic analysis.
Mitigation Recommendations
No official patch or fix is applicable as this is a web-based malvertising campaign. Users should avoid downloading financial or cryptocurrency-related applications from social media ads or sponsored search results. It is recommended to obtain executable files only from official company websites and verify the digital signature and publisher before execution. Security teams should be aware of this delivery technique but no direct remediation is provided by vendors. Patch status is not yet confirmed — check vendor advisories for updates.
Technical Details
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/malicious-sites-use-javascript-to-build-malware-in-browser-memory/","fetched":true,"fetchedAt":"2026-07-25T15:22:07.513Z","wordCount":863}
Threat ID: 6a64d49f9c2644c7f886b7f7
Added to database: 07/25/2026, 15:22:07 UTC
Last enriched: 07/25/2026, 15:22:17 UTC
Last updated: 07/26/2026, 01:53:08 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.