Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

Jul 25, 2026

A malvertising operation dubbed SourTrade is making victims’ browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL.

Confiant, which detailed the campaign on July 23, 2026, said it has operated since late 2024 and impersonated TradingView, Solana, and Luno to target retail traders and

Get Free Report & Network Analysis

Please check your email for the free report.