Security · 16h ago
Malvertising Campaign Uses Browser to Assemble Malware on the Fly
A malvertising operation called SourTrade has been active since late 2024, using a legitimate Bun runtime to have victims' browsers build the final Windows executable piece by piece. The campaign, detailed by Confiant on July 23, 2026, impersonates TradingView, Solana, and Luno to target retail traders. This technique evades traditional detection by avoiding a single malicious file from a fixed URL.
Meridian48 take
The approach highlights how attackers are increasingly leveraging legitimate tools to bypass security, making detection harder for both users and antivirus software.
Read the full reporting
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable →
The Hacker News
malvertisingbrowser-based-attack