Close Menu
NCIJ Network NCIJ Network
    What's Hot

    EU expands HTX crackdown as Russia-linked crypto network keeps shifting its financial rails

    July 25, 2026

    Iran’s government spars with state TV as mediators push talks with US | US-Israel war on Iran News

    July 25, 2026

    Trump threatens new tariffs against EU over Google fine

    July 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • EU expands HTX crackdown as Russia-linked crypto network keeps shifting its financial rails
    • Iran’s government spars with state TV as mediators push talks with US | US-Israel war on Iran News
    • Trump threatens new tariffs against EU over Google fine
    • Troy Jackson Picked to Replace Platner as Democratic Nominee in Maine Senate Race
    • Synth historian Oli Freke will spend big on a good bicycle
    • DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
    • Investment Giant Fidelity Backs Clarity Act
    • Superagers keep youthful memories but their DNA does not explain why
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, July 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Malicious sites use JavaScript to build malware in browser memory

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 25, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory.

    The operation has been active since late 2024 and is localized to 25 languages in 12 countries, primarily in Asia Pacific and Latin America.

    A filtering system ensures that only real targets (retail traders and crypto investors) land on the malicious pages, while researchers, scanners, and security bots are redirected to blank pages.

    image

    Ad security platform Confiant says that the campaign’s design stands out through its use of the web browser as “a local assembly pipeline” for the malware.

    Although the fake portals feature a download button, a ReactJS library on the landing page prepares the browser for a managed download flow, a process typically used for handling various types of file transfers.

    Fake Trading View site
    Fake TradingView site
    Source: Confiant

    According to Confiant’s analysis, the page first registers a service worker, which acts as a download manager and helps build the malware file incrementally.

    In the first stage, the page sets up a shared worker that acts as an engine that assembles the malware from components received in the next steps of the attack.

    The researchers say that in the second stage “the landing page uses its SharedWorker to request itself for a ‘/config’ response” with seed and size parameters that are randomized and specific for each session.

    By rotating these parameters, the threat actors make sure that the resulting malware file has a unique hash to bypass static detection.

    Confiant explains that “‘/config’ is an assembly response rather than a normal download response. It returns a template and the inputs the browser needs to build the file locally.”

    Remote components retrieved this way and the locally generated bytes are then used to create the malicious payload from a clean version of the Bun executable.

    After building the final malware executable, the fake download page hands it to the service worker at the beginning of the process and triggers a same-origin download path.

    “From the browser’s point of view, the user is downloading an executable from the landing page domain,” Confiant researchers say, and the mark-of-the-web tag is added, despite some of the components originating from a different source.

    The advantage of this technique is that no finished file is transmitted over the network, making detection less likely, and analysis becomes more challenging.

    Confiant says that earlier variants of the SourTrade campaign used the StreamSaver project on GitHub to deliver the malicious payload. Since April, though, the operation switched to the same-origin ServiceWorker delivery method.

    While Confiant researchers do not reveal the nature of the payload, they found evidence supporting a Bitdefender report in 2025 about a resilient  malvertising campaign that used StreamSaver to distribute malware.

    Bitdefender found that the payload had the following capabilities:

    • intercept all user network traffic (acting as a proxy)
    • collect cookie and password data
    • record keystrokes (keylogging) and take screenshots
    • steal cryptocurrency wallet data
    • establish long-term persistence

    Since the SourTrade campaign targets retail traders and crypto investors, users engaged in these activities are advised to avoid downloading financial or cryptocurrency apps from social media advertisements or sponsored search results.

    The researchers advise getting executable files from the company’s official website. As an added precaution, they should verify the installer’s digital signature and publisher before running it.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    browser Build JavaScript Malicious Malware memory sites
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

    ShinyHunters data leaks fuel $2,000 sextortion email scam

    Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

    Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

    CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

    Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    EU expands HTX crackdown as Russia-linked crypto network keeps shifting its financial rails

    July 25, 2026

    Iran’s government spars with state TV as mediators push talks with US | US-Israel war on Iran News

    July 25, 2026

    Trump threatens new tariffs against EU over Google fine

    July 25, 2026

    Troy Jackson Picked to Replace Platner as Democratic Nominee in Maine Senate Race

    July 25, 2026
    Latest Posts

    Trump slaps 50% tariffs on Canada and Carney vows to ‘intensify’ trade talks

    July 21, 2026

    How Two Brothers Dug for Dead Relatives: With a Shovel and a Kitchen Knife

    July 21, 2026

    Chile floods: Towns evacuated following heavy rain in Coquimbo

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    EU expands HTX crackdown as Russia-linked crypto network keeps shifting its financial rails

    July 25, 2026

    Iran’s government spars with state TV as mediators push talks with US | US-Israel war on Iran News

    July 25, 2026

    Trump threatens new tariffs against EU over Google fine

    July 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.