ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
HIGH Cybersecurity

SourTrade malvertising assembles Windows malware in-browser using Bun

Source headline: Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

Threat level High
Signal strength 75/100
Source confidence 1 source
Published 5 hours ago

Intelligence Summary

A malvertising campaign called SourTrade delivers malware in pieces and relies on the victim’s browser to assemble the final Windows executable. Instead of hosting a single fixed payload, it uses a legitimate Bun runtime as a base component for the built executable. The campaign has been active since late 2024 and has targeted retail traders by impersonating brands such as TradingView, Solana, and Luno. Security researchers say the approach reduces reliance on one direct malicious download URL. Users should be cautious with unexpected trading-related prompts and keep browsers and endpoints updated while avoiding sketchy ad links.

Recommended Action

Review affected assets, schedule urgent remediation, and monitor related indicators.

Topics

#malvertising #browser-based #bun-runtime #trading-impersonation #windows-malware
Original reporting The Hacker News Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
Open original source