Node.js Malware Campaign Targets Crypto Users with Fake Binance and TradingView Installers
Microsoft is drawing attention to a persistent malvertising effort that uses Node.js to distribute malicious payloads that can steal and exfiltrate data.
The behavior, which was initially discovered in October 2024, involves luring users into installing a malicious installer from phony websites that pose as trustworthy applications, such as Binance or TradingView, using lures associated with bitcoin trading.
A dynamic-link library ("CustomActions.dll") is included in the downloaded installer and is in charge of leveraging Windows Management Instrumentation (WMI) to gather basic system information and scheduling a job to establish persistence on the host.
The DLL uses "msedge_proxy.exe" to open a browser window that shows the authentic cryptocurrency trading website in an effort t...

