SourTrade: The new hack that uses your browser to build malware
The SourTrade campaign redefines malvertising by forcing the user's browser to assemble malware piece by piece, bypassing traditional detection methods.

The end of traditional malware: The SourTrade threat
The cybersecurity industry is facing a worrying evolution in malicious code distribution techniques. Recent research by Confiant has revealed the existence of SourTrade, a sophisticated malvertising operation that has been active since late 2024. Unlike conventional attacks, this campaign does not download a complete executable from a server; instead, it fragments the malware so that the victim's own browser reconstructs it.
This method allows attackers to evade security filters that analyze downloaded files, as the final file only exists after being assembled in the user's local environment, using the legitimate Bun runtime as a foundation.
An attack camouflaged under trusted brands
The operators behind this hack have demonstrated a high capacity for impersonation, using the names of prestigious financial platforms such as TradingView, Solana, and Luno. The goal is clear: to attract retail traders who trust these tools to manage their digital assets. By interacting with these fake ads, the user initiates a silent process where the browser inadvertently downloads the fragmented components and compiles them.
"SourTrade uses the legitimate Bun runtime to hide its intentions, making the assembly process appear to be a standard technical browser operation," Confiant experts note.
The growing sophistication of cybercrime
These types of tactics demonstrate that, in the face of increased online surveillance, malicious actors are turning to system architecture to cover their tracks. Much like what we saw in the case of BlueNoroff launches phishing kit: a new hack and malware threat, attackers are investing in more complex methods to bypass user defenses.
The implications of this technique are serious, as it:
- Hinders detection: Traditional antivirus software does not find a single malicious file to scan during the download.
- Abuse of legitimacy: By using
Bun, the malware mimics legitimate development processes. - Persistence: Once assembled, the executable can open the door to other threats, such as the deployment of ransomware or the theft of banking credentials.
Conclusion: How to protect yourself?
The vulnerability does not necessarily lie in the browser, but in the trust placed in ads that appear legitimate. It is vital to exercise extreme caution when clicking on sponsored links in search engines, even if the brand seems familiar. Modern cybersecurity requires a skeptical attitude toward any unexpected download, always remembering that attackers are constantly looking for new ways to turn our own tools against us.
Source: The Hacker News (2026).
Related articles
26 de julio de 2026
SourTrade: El nou hack que utilitza el teu navegador per crear malware
La campanya SourTrade redefineix el malvertising en obligar el navegador de l'usuari a assemblar malware peça a peça, evitant així els mètodes de detecció.
26 de julio de 2026
SourTrade: El nuevo hack que utiliza tu navegador para crear malware
La campaña SourTrade redefine el malvertising al obligar al navegador del usuario a ensamblar malware pieza por pieza, evitando los métodos de detección.
25 de julio de 2026
BlueNoroff llança un kit de phishing: una nova amenaça de hack i malware
El grup BlueNoroff utilitza dominis falsos de Zoom per perfil·lar criptocarteres i desplegar malware avançat mitjançant tècniques d'enginyeria social.
25 de julio de 2026
BlueNoroff Launches Phishing Kit: A New Hack and Malware Threat
The BlueNoroff group uses fake Zoom domains to profile crypto wallets and deploy advanced malware through social engineering techniques.
Loading comments...