Malvertising builds malware in browser memory
🛡️ A widespread malvertising campaign uses fake Solana, Luno, and TradingView pages with malicious JavaScript that assembles malware directly in the browser's memory. The operation, active since late 2024 across 12 countries, filters out researchers and scanners while delivering customized payloads to retail traders and crypto investors. Confiant found the pages register service and shared workers to piece together a unique executable from remote components and local bytes, avoiding transmission of a finished file to evade detection.