hacker-news · Crawled Jul 25, 2026
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
2 IoCs 1 Malware
Read original article ↗
AI Summary
A malvertising campaign dubbed SourTrade has been active since late 2024, targeting retail traders and cryptocurrency investors across 12 countries by impersonating legitimate services like TradingView, Solana, and Luno. The attack uses a legitimate Bun runtime to dynamically assemble Windows executables within the victim's browser, leveraging ServiceWorker and SharedWorker to build malware pieces in memory. This technique avoids delivering a complete malicious binary over the network, instead using Base64-encoded components and AES-CTR-generated streams to create unique per-session payloads, evading hash-based detection.
AI-extracted · verify before operational use