hacker-news · Crawled Jul 25, 2026

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

2 IoCs 1 Malware
Read original article ↗

AI Summary

A malvertising campaign dubbed SourTrade has been active since late 2024, targeting retail traders and cryptocurrency investors across 12 countries by impersonating legitimate services like TradingView, Solana, and Luno. The attack uses a legitimate Bun runtime to dynamically assemble Windows executables within the victim's browser, leveraging ServiceWorker and SharedWorker to build malware pieces in memory. This technique avoids delivering a complete malicious binary over the network, instead using Base64-encoded components and AES-CTR-generated streams to create unique per-session payloads, evading hash-based detection.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 2 extracted

Type Value Detail
Domain purelogicbox[.]org Details →
GitHub Repo https://github.com/jimmywarting/StreamSaver.js Details →

MITRE ATT&CK TTPs 5 techniques