discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Malicious sites use JavaScript to build malware in browser memory

A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. The operation has been active since late 2024 and is localized to 25 languages in 12 countries, p…

By Bill Toulas·Jul 25·bleepingcomputer.com·2 min read

Intelligence analysis by Llama

Malicious sites use JavaScript to build malware in browser memory
Image: bleepingcomputer.com

The campaign's design stands out through its use of the web browser as a local assembly pipeline for the malware. Although the fake portals feature a download button, a ReactJS library on the landing page prepares the browser for a managed download flow, a process typically used for handling various types of file transfers.

Why it matters

This story matters to someone following Security because it highlights a sophisticated malvertising campaign that uses JavaScript to build malware in browser memory, making detection less likely and analysis more challenging.

Imagine you're browsing the internet and you come across a fake website that looks like a real one. This website has a special code that helps it build a bad program right in your browser. This program can do bad things like steal your passwords or take pictures of what you're typing. It's like a sneaky way for the bad guys to get what they want without you even knowing it.

Analysis

A Malicious Malvertising Campaign

A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. The operation has been active since late 2024 and is localized to 25 languages in 12 countries, primarily in Asia Pacific and Latin America.

How It Works

The campaign's design stands out through its use of the web browser as a local assembly pipeline for the malware. Although the fake portals feature a download button, a ReactJS library on the landing page prepares the browser for a managed download flow, a process typically used for handling various types of file transfers.

The Advantage of This Technique

The advantage of this technique is that no finished file is transmitted over the network, making detection less likely, and analysis becomes more challenging. Confiant researchers do not reveal the nature of the payload, but they found evidence supporting a Bitdefender report in 2025 about a resilient malvertising campaign that used StreamSaver to distribute malware.

The Payload's Capabilities

The payload had the following capabilities: intercept all user network traffic (acting as a proxy), collect cookie and password data, record keystrokes (keylogging), and take screenshots, steal cryptocurrency wallet data, and establish long-term persistence.

Key points

  • A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory.
  • The operation has been active since late 2024 and is localized to 25 languages in 12 countries, primarily in Asia Pacific and Latin America.
  • The campaign's design stands out through its use of the web browser as a local assembly pipeline for the malware.
  • The advantage of this technique is that no finished file is transmitted over the network, making detection less likely, and analysis becomes more challenging.
The Upside

If this development plays out positively, it could lead to more effective detection and analysis of similar malvertising campaigns, ultimately reducing the risk of malware distribution through fake websites.

The Downside

The realistic downside risks or failure modes of this campaign include the potential for the malware to evade detection, the possibility of the campaign spreading to more countries and languages, and the risk of the malware being used for more sophisticated attacks.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagsmalvertisingmalwarejavascriptbrowsersecurity

Author

Bill Toulas

Intelligence analysis by

Llama

Published

Jul 25, 2026

Source

bleepingcomputer.com

Share

Topics

malvertisingmalwarejavascriptbrowsersecurity

Related

More from this desk

Jul 25·bleepingcomputer.com

ShinyHunters data leaks fuel $2,000 sextortion email scam

Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. The emails claim to come from ShinyHunters and tell recipients that hackers compromised their devices after o…

Jul 25·thehackernews.com

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patch Available

A critical unauthenticated RCE flaw (CVE-2026-16723) in Alibaba's Fastjson 1.x library is being actively exploited against Spring Boot applications, but no patch is available from the maintainer.

Jul 25·thehackernews.com

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

Phishing campaigns targeting financial institutions have evolved, with attackers now synchronizing their activity with victims in real-time, authenticating against legitimate insurance portals as victims unknowingly complete the login process.

Jul 25·thehackernews.com

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Threat actors linked to the Cl0p ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign.