A malvertising campaign uses fake Solana, Luno, and TradingView pages with malicious JavaScript that assembles malware directly in browser memory.