Watchers Lab

← Back to Community

Community discussions are public to read. To post, reply, or watch members, please sign in or create an account.

Malicious sites use JavaScript to inject malware into browser

Posted by DiabloChops on 07/25/2026 at 06:25 PM

A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. The operation has been active since late 2024 and is localized to 25 languages in 12 countries, primarily in Asia Pacific and Latin America. A filtering system ensures that only real targets (retail traders and crypto investors) land on the malicious pages, while researchers, scanners, and security bots are redirected to blank pages.

Comments

No comments yet.

Sign in or create an account to reply to this discussion.