logo

Malicious sites use JavaScript to build malware in browser memory

ID: d4554650-f44c-5ea9-8aac-1f0a20f1b55e

STIX ID: report--d4554650-f44c-5ea9-8aac-1f0a20f1b55e

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-07-25

Date Updated: 2026-07-25

Author: Bill Toulas

...
...

A malvertising campaign known as "SourTrade" is impersonating Solana, Luno, and TradingView pages and using malicious JavaScript (ServiceWorker/SharedWorker infrastructure) to assemble a unique malware executable in the browser, bypassing delivery of a finished file to evade detection. Active since late 2024 across 12 countries and 25 languages, the operation targets retail traders and crypto investors and employs filtering to avoid researchers; reported payload capabilities include intercepting traffic, stealing cookies/passwords and crypto wallet data, keylogging, screenshots, and persistence, so users are advised to download software only from official sites and verify digital signatures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.