← Back to Feed

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

July 25, 2026 · The Hacker News · Severity: HIGH

A malvertising operation called SourTrade makes victims' browsers build the final Windows executable themselves using the Bun runtime instead of serving a complete malicious file from a fixed URL. Active since late 2024, it impersonates TradingView, Solana, and Luno to target retail traders and cryptocurrency investors across 12 countries in 25 languages. Landing pages fingerprint visitors, showing empty pages to researchers and convincing copies of impersonated services to selected targets.

Key Takeaways

  • SourTrade malvertising lets victims' browsers build the final Windows binary using Bun runtime, evading static file detection.
  • The delivery is click-based: victims click the ad, then click again to start the malicious download chain.
☕ Buy a Coffee