Malvertising Campaign Uses Browsers to Assemble Malware

A new malvertising scheme known as SourTrade is cleverly utilizing browsers to construct malicious executables, leveraging a legitimate runtime environment.

3 min readCybersecurity

A recent investigation has uncovered a sophisticated malvertising campaign named SourTrade, which has been active since late 2024. This operation is particularly notable for its unique approach: instead of delivering a complete malicious executable from a single source, it breaks the malware into smaller pieces. Victims' web browsers are then tasked with assembling these fragments into a final executable file. This method employs a legitimate Bun runtime, making detection more challenging. The campaign has targeted retail traders by masquerading as trusted platforms such as TradingView, Solana, and Luno. According to security firm Confiant, which reported on this operation on July 23, 2026, the strategy not only enhances the effectiveness of the attack but also complicates the efforts of cybersecurity defenses. By leveraging legitimate software components, SourTrade increases the likelihood that users will unknowingly execute the malware, leading to potential data breaches and financial losses.

Cybersecurity