#6
The Hacker News
general
July 25, 2026 at 18:48 UTC
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
By [email protected] (The Hacker News)
AI Summary
The SourTrade malvertising campaign, active since late 2024 and detailed by Confiant on July 23, 2026, has victims' browsers assemble the final Windows malware executable in memory using a legitimate Bun JavaScript runtime — avoiding delivery of a single detectable malicious file from a fixed URL. The operation impersonated TradingView, Solana, and Luno to target retail traders and crypto users. This browser-side assembly technique presents a significant challenge for traditional network-based malware detection controls.
Relevance score: 80.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →