SourTrade Malvertising Campaign Leverages Browser-Side Assembly of Malware via Bun Runtime
A malvertising campaign named SourTrade uses browser-side assembly of malware by splitting payloads and leveraging the Bun runtime to construct Windows executables client-side, evading traditional detection methods. The technique involves dynamic configuration downloads and per-session file generation, complicating hash-based detection and requiring analysis of the full delivery chain.
A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL.
Confiant, which detailed the campaign on July 23, 2026, said it has operated since late 2024 and impersonated TradingView, Solana, and Luno to target retail traders and
*** END OF TRANSMISSION ***