A malvertising campaign called SourTrade tricks browsers into building Windows executables using a legitimate Bun runtime. Targeting retail traders via fake TradingView, Solana, and Luno ads, it evades detection by assembling malware in pieces.
Imagine clicking a harmless-looking ad and, without realizing it, your browser starts assembling a malicious program piece by piece. That's exactly what a new malvertising campaign called SourTrade is pulling off. Instead of dropping a single, obvious malware file from a shady URL, it tricks your browser into building the final Windows executable itself using a legitimate Bun runtime as its base.
Security firm Confiant detailed this campaign on July 23, 2026, noting it has been active since late 2024. The operation impersonates popular platforms like TradingView, Solana, and Luno to target retail traders and crypto investors. It's a clever twist on an old threat, and it raises serious questions about how we trust our browsers.
### How SourTrade Works: A Step-by-Step Look
The attack unfolds in a few quiet stages. First, a malvertising ad appears on a legitimate site—maybe a trading forum or a crypto news page. If you click it, you're redirected through a chain of URLs that eventually lands on a page hosting a malicious script.
Here's where it gets interesting. That script doesn't download a full malware executable. Instead, it pulls in a legitimate Bun runtime (a modern JavaScript runtime similar to Node.js) and then feeds it small, encrypted pieces of code. The browser, acting on instructions, assembles these pieces into a working Windows executable right there in memory. No single file is ever served from a fixed URL, making detection much harder.
- **Step 1:** User clicks a malvertising ad.
- **Step 2:** Redirect chain leads to a malicious landing page.
- **Step 3:** Browser downloads a legitimate Bun runtime.
- **Step 4:** Encrypted code fragments are fetched and assembled.
- **Step 5:** The final executable runs on the Windows machine.
This approach bypasses many traditional security tools that look for known malware signatures or suspicious file downloads. Because the Bun runtime is legitimate, it doesn't raise red flags. And the malware pieces are small and encrypted, so they can slip through network filters.
### Why Retail Traders Are in the Crosshairs
SourTrade specifically impersonates TradingView, Solana, and Luno—three names that resonate with retail traders and crypto enthusiasts. These platforms are trusted by millions for charting, trading, and managing digital assets. By faking login pages or promotional offers, attackers trick users into clicking links that lead to the malvertising chain.
> "The attackers are betting on trust. If you think you're logging into TradingView, you're less likely to question a pop-up ad that looks official." — Emily Davis, Head of Digital Privacy and Antidetect Browser Solutions at Antidetectbrowsershub
Retail traders often operate from personal devices with less robust security than corporate networks. They're also under time pressure—markets move fast, and a fake ad promising "exclusive signals" can be hard to resist. This combination of trust and urgency makes them ideal targets.
### Protecting Yourself Against Browser-Built Malware
So, what can you do? First, don't click ads for financial platforms. Bookmark the official URLs for TradingView, Solana, or Luno and always navigate there directly. Use an ad blocker to reduce malvertising exposure, but remember that no tool is 100% effective.
Second, consider using an antidetect browser for sensitive activities. These browsers create isolated profiles that prevent malware from accessing your system's core functions. They also help mask your digital fingerprint, making it harder for attackers to track you across sessions.
- **Use ad blockers** to minimize malvertising risk.
- **Bookmark official sites** instead of clicking ads.
- **Keep your browser updated** to patch vulnerabilities.
- **Consider antidetect browsers** for high-risk tasks like trading.
Finally, stay skeptical. If an ad promises something too good to be true—like free crypto or guaranteed trading signals—it probably is. The SourTrade campaign is a reminder that even your browser can be turned against you.
### The Bigger Picture: Evolving Threats
SourTrade is just one example of how malvertising is evolving. By using legitimate tools like Bun runtime, attackers make their operations harder to detect. This trend toward "living off the land" techniques means security tools must adapt to monitor behavior, not just static files.
For now, the best defense is awareness. Know that your browser can be weaponized. Take steps to protect it. And if you're a retail trader, treat every ad with a healthy dose of caution.
This isn't about fear—it's about staying one step ahead. After all, the internet is full of clever tricks, but you don't have to fall for them.