SyncWave Blog
Cybersecurity 3 min read 77

SourTrade: The new hack that uses your browser to build malware

The SourTrade campaign redefines malvertising by forcing the user's browser to assemble malware piece by piece, bypassing traditional detection methods.

cyber security warning

The end of traditional malware: The SourTrade threat

The cybersecurity industry is facing a worrying evolution in malicious code distribution techniques. Recent research by Confiant has revealed the existence of SourTrade, a sophisticated malvertising operation that has been active since late 2024. Unlike conventional attacks, this campaign does not download a complete executable from a server; instead, it fragments the malware so that the victim's own browser reconstructs it.

This method allows attackers to evade security filters that analyze downloaded files, as the final file only exists after being assembled in the user's local environment, using the legitimate Bun runtime as a foundation.

An attack camouflaged under trusted brands

The operators behind this hack have demonstrated a high capacity for impersonation, using the names of prestigious financial platforms such as TradingView, Solana, and Luno. The goal is clear: to attract retail traders who trust these tools to manage their digital assets. By interacting with these fake ads, the user initiates a silent process where the browser inadvertently downloads the fragmented components and compiles them.

"SourTrade uses the legitimate Bun runtime to hide its intentions, making the assembly process appear to be a standard technical browser operation," Confiant experts note.

The growing sophistication of cybercrime

These types of tactics demonstrate that, in the face of increased online surveillance, malicious actors are turning to system architecture to cover their tracks. Much like what we saw in the case of BlueNoroff launches phishing kit: a new hack and malware threat, attackers are investing in more complex methods to bypass user defenses.

The implications of this technique are serious, as it:

  • Hinders detection: Traditional antivirus software does not find a single malicious file to scan during the download.
  • Abuse of legitimacy: By using Bun, the malware mimics legitimate development processes.
  • Persistence: Once assembled, the executable can open the door to other threats, such as the deployment of ransomware or the theft of banking credentials.

Conclusion: How to protect yourself?

The vulnerability does not necessarily lie in the browser, but in the trust placed in ads that appear legitimate. It is vital to exercise extreme caution when clicking on sponsored links in search engines, even if the brand seems familiar. Modern cybersecurity requires a skeptical attitude toward any unexpected download, always remembering that attackers are constantly looking for new ways to turn our own tools against us.


Source: The Hacker News (2026).

Share:

Comments

Loading comments...

Contact

Want to get in touch?

Questions, suggestions or proposals — write to us and we will respond.