Security News

Cybersecurity news aggregator

MEDIUM Attacks SC Media

Malvertising campaign assembles malware in browser

  • What: Malvertising campaign assembles malware in browser
  • Impact: Users in Asia Pacific and Latin America at risk of browser-based malware
Read Full Article →

Application security , Third-party code Malvertising campaign assembles malware in browser July 27, 2026 Share By SC Staff (Adobe Stock) A large-scale malvertising campaign is using fake websites for Solana, Luno, and TradingView, employing malicious JavaScript to assemble malware directly in the user's browser. This operation, active since late 2024, targets retail traders and crypto investors across 12 countries, primarily in the Asia Pacific and Latin America regions, as first reported by Bleeping Computer. The campaign employs a sophisticated technique where the web browser acts as a local assembly pipeline for malware. Fake download pages register a service worker to manage the download process, incrementally building the malware file. A shared worker then acts as an engine, requesting configuration data with randomized parameters to ensure each malware file has a unique hash, bypassing static detection. The assembled malware is built from retrieved remote components and locally generated bytes using a clean version of the Bun executable. This method avoids transmitting a finished file over the network, making detection and analysis more challenging. Earlier variants used StreamSaver, but the campaign has since switched to the ServiceWorker delivery method. While the payload's exact nature is not disclosed, it is believed to be similar to malware previously reported to intercept network traffic, steal credentials and cryptocurrency, log keystrokes, and establish persistence. Users are advised to download financial applications only from official websites and verify installer signatures. Source: Bleeping Computer SC Staff Related AI/ML AI plans are being approved. Recovery plans are not Paul Wagenseil July 27, 2026 Do you spend more time managing AI agents than you save by using them? Here's how to make your ROI on agentic deployment. AI/ML Balancing lead generation, growth, and security in the age of AI search Solomon Adote July 27, 2026 AI search visibility demands smarter bot security, not open access. AI/ML Phishing the agent: Why identity controls are essential to secure and manage AIs Paul Wagenseil July 27, 2026 Guardrails cannot serve as the primary security boundary for AI agents. Identity controls impose firmer limits. Related Events Cybercast Bridging the Gap from CISO-Developed Tools to Black Hat Hype: What AI Security Leaders Should Watch Next On-Demand Event Cybercast Protecting Application User Data for Better Privacy, Governance, and Compliance On-Demand Event Cybercast The Next Evolution of Application Security: AI- Accelerated DevSecOps On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Banner Browser Cache Cramming Common Gateway Interface (CGI) Client Cookie DLL Injection Dynamic Link Library You can skip this ad in 5 seconds

Share this article