SourTrade malvertising assembles Windows malware in-browser using Bun
Source headline: Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
Intelligence Summary
A malvertising campaign called SourTrade delivers malware in pieces and relies on the victim’s browser to assemble the final Windows executable. Instead of hosting a single fixed payload, it uses a legitimate Bun runtime as a base component for the built executable. The campaign has been active since late 2024 and has targeted retail traders by impersonating brands such as TradingView, Solana, and Luno. Security researchers say the approach reduces reliance on one direct malicious download URL. Users should be cautious with unexpected trading-related prompts and keep browsers and endpoints updated while avoiding sketchy ad links.
Recommended Action
Review affected assets, schedule urgent remediation, and monitor related indicators.