Home / Jul 26, 2026 / Story
0
#6 The Hacker News general July 25, 2026 at 18:48 UTC

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

By [email protected] (The Hacker News)

AI Summary

The SourTrade malvertising campaign, active since late 2024 and detailed by Confiant on July 23, 2026, has victims' browsers assemble the final Windows malware executable in memory using a legitimate Bun JavaScript runtime — avoiding delivery of a single detectable malicious file from a fixed URL. The operation impersonated TradingView, Solana, and Luno to target retail traders and crypto users. This browser-side assembly technique presents a significant challenge for traditional network-based malware detection controls.

Relevance score: 80.0/100

# More from July 26