SECURITYTHE HACKER NEWS
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
A malvertising operation named SourTrade uses a legitimate Bun runtime to make victims' browsers construct Windows malware, avoiding direct delivery of a complete malicious file. The campaign, impersonating TradingView, Solana, and Luno, targets retail traders.
Mentioned
Related Signal
Adjacent reporting
- Malicious sites use JavaScript to build malware in browser memory
- Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS
- Malicious trading website drops malware that hands your browser to attackers
- Researchers flag TrapDoor malware campaign targeting crypto developer environments including Aptos, Sui and Solana
- Microsoft found malware that hijacks crypto wallets and spreads through USB sticks