A malvertising campaign called SourTrade uses a legitimate Bun runtime to make victims' browsers assemble Windows executables from pieces, targeting retail traders by impersonating TradingView, Solana, and Luno since late 2024.
Imagine you’re browsing a site that looks like a trusted trading platform. You see an ad, click it, and your browser starts downloading something. But it’s not a complete file. It’s pieces. And then, without you knowing, your browser builds the final malicious executable itself.
That’s the reality of a malvertising campaign called SourTrade. It’s been running since late 2024, and it’s targeting retail traders by impersonating platforms like TradingView, Solana, and Luno. Confiant, a security firm, broke the story on July 23, 2026, and what they found is a clever twist on how malware gets delivered.
Instead of serving one complete malicious file from a fixed URL, SourTrade uses a legitimate Bun runtime as its base. Bun is a fast JavaScript runtime, and it’s perfectly legal. The bad guys use it to build the Windows executable right in your browser. Think of it like getting all the ingredients for a cake delivered separately, and then your oven bakes it for them.
### How the Attack Works
The process is sneaky. First, the malvertising ad lures you in. It looks like a promotion from a real trading brand. Once you click, your browser starts fetching small chunks of code. These chunks are harmless on their own, which helps them slip past security filters.
Then, the Bun runtime assembles them into a full Windows executable. This executable can do anything from stealing your login credentials to installing ransomware. Because the assembly happens locally, traditional security tools that scan incoming files often miss it.
Confiant noted that the campaign has been active for over a year. It impersonates three major trading platforms to seem legit. Retail traders are the primary targets because they’re more likely to click ads related to crypto and trading.
### What Makes This Different
Most malware comes as a single file from a known server. That makes it easier to block with antivirus or firewall rules. SourTrade flips that model. By breaking the malware into pieces and using a legitimate tool like Bun, it sidesteps many detection methods.
It’s like a thief mailing you the parts of a lockpick kit one at a time, and then asking you to assemble it. Your browser becomes an unwitting accomplice. This technique is called “fileless” or “living-off-the-land” malware, but SourTrade adds a new layer by using a runtime that’s already on many systems.
### Who Should Be Worried
If you’re a retail trader who uses platforms like TradingView, Solana, or Luno, you’re in the crosshairs. But honestly, anyone who clicks online ads could be at risk. The campaign targets traders specifically, but similar techniques could be used against other groups.
Here’s a quick list of warning signs:
- Ads that promise high returns or urgent deals.
- URLs that look slightly off from the real platform.
- Unexpected downloads or browser slowdowns.
### How to Protect Yourself
First, think before you click. If an ad looks too good to be true, it probably is. Stick to typing URLs directly into your browser instead of clicking ads. Use a reputable ad blocker to reduce exposure.
Second, keep your browser and operating system updated. Security patches can close loopholes that malvertising exploits. Consider using an antidetect browser if you manage multiple accounts or need extra privacy layers. These browsers can help mask your digital fingerprint, making it harder for attackers to track you.
Third, run regular scans with a good antivirus program. Even if the malware assembly is sneaky, behavioral detection tools can spot odd activity like your browser suddenly compiling code.
### The Bigger Picture
SourTrade is a reminder that cyber threats keep evolving. The bad guys are using legitimate tools to do dirty work. They’re not just sending viruses anymore; they’re making your own machine build them. This shifts the responsibility onto users to be more vigilant.
For professionals in the antidetect browser space, this is a call to stay ahead. Tools that monitor browser behavior and detect anomalous processes are becoming essential. If you’re in digital marketing, affiliate management, or crypto trading, you need layers of protection beyond basic antivirus.
Confiant’s report shows that SourTrade has been active for over a year without being widely detected. That means similar campaigns could be running right now. Stay sharp, keep your tools updated, and never trust an ad at face value.