“When you close the browser and open a new one is the malware still active?”
That is exactly what I am testing now. I am hoping they are completely separate so that the scripts cache from one does not affect the other. But I am afraid that by default they are tied together with the same cache. If so there needs to be away to keep them isolated from each other to help with this problem. Might have to make a custom route to a second unique cache.
So they can capture things like your bank account user name and password, even if you use a password safe?