Malware Ads Now Build Themselves Inside Your Browser

A malvertising campaign fakes trading and crypto sites, then quietly assembles Windows malware piece by piece inside your browser.

Malware Ads Now Build Themselves Inside Your Browser

A New Twist on an Old Scam

Security researchers have uncovered a large malvertising operation that hides malware in a way most antivirus tools were not built to catch. Instead of tricking someone into downloading a single infected file, the attackers split their malicious program into small, harmless-looking pieces. Those pieces travel separately to the victim's computer, and only once they arrive does the browser quietly stitch them together into a working piece of malware. By the time the full program exists, it is already sitting in the computer's memory rather than showing up as a suspicious file on the hard drive.

This campaign, which researchers say has been running since late 2024, has been spotted impersonating well known names in trading and cryptocurrency, including TradingView, Solana, and the crypto exchange Luno. The fake pages are designed to look convincing enough that everyday investors and traders click through without a second thought.

How the Trick Works

The scam starts with an ad or a link that leads to a fake version of a trusted website. These pages are built to closely copy the branding, layout, and tone of the real services, which makes them hard to spot at a glance. Once a visitor lands on the page, hidden code goes to work in the background.

Rather than downloading one complete malicious program, the page loads a legitimate piece of software called the Bun runtime, which is normally used by developers to run JavaScript code quickly. The attackers use this legitimate tool as a hidden foundation, feeding it small chunks of malicious code over time. Piece by piece, the browser assembles these chunks into a full Windows executable, all inside the computer's active memory.

Because the malware never appears as a single downloaded file, many traditional security tools that scan files on a hard drive have nothing obvious to flag. The final harmful program essentially builds itself on the victim's own machine, using the browser as the workshop.

Why This Matters for Everyday Users

This method matters because it targets a blind spot in how a lot of home antivirus software works. Many tools are designed to check files as they are saved to a computer. When malware assembles itself only in memory and never touches the disk in a complete, recognizable form, it becomes much harder for those tools to catch it before damage is done.

The people most at risk here are retail traders and everyday crypto users, since the campaign specifically mimics platforms that group relies on for charts, trading, and account access. Someone searching for trading tools or crypto exchange information could easily click a malicious ad or search result without realizing the destination site is fake.

Once the malware is running, it typically aims to steal sensitive information such as login credentials, crypto wallet details, or personal financial data. For someone who trades or holds digital assets, that can mean direct financial loss.

Warning Signs to Watch For

There is no flashing warning that tells a visitor a page is fake, but there are patterns worth watching for.

  • Ads or search results that lead to slightly misspelled or unusual web addresses claiming to be TradingView, Solana, or Luno.
  • Sites that ask you to download software or run a file to "verify" your account or access a trading dashboard.
  • Unexpected pop-ups or browser prompts asking for permission to run scripts or install extensions right after clicking an ad.
  • Pages that load slowly or behave oddly compared to the official site you normally use.

What You Should Do

Type website addresses directly into your browser instead of clicking ads or links from search results when visiting trading platforms or crypto exchanges. Bookmark the official sites you use regularly so you always land on the real page.

Keep your browser and operating system updated, since patches often close the gaps these campaigns rely on. Consider using an ad blocker, which can prevent malicious ads from loading in the first place. If you trade or hold crypto assets, turn on two factor authentication wherever it is offered, so stolen passwords alone are not enough to drain an account.

If you think you may have visited one of these fake pages, run a full scan with updated antivirus software, change your passwords from a separate, trusted device, and monitor your accounts closely for unfamiliar activity in the days that follow.