A malvertising chain tied to trading and crypto lures shows how ServiceWorkers and SharedWorkers can be repurposed for runtime assembly inside the browser, complicating file-based defense.