A malvertising campaign is reportedly using browser-side assembly to build its payload in memory, a tactic that weakens file-based detection and complicates incident response.