Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base. The campaign has operated since late 2024 and impersonated TradingView, Solana, and Luno to target retail trade…
Intelligence analysis by Llama

The malvertising operation, dubbed SourTrade, uses a legitimate Bun runtime to make victims' browsers build the final Windows executable. The campaign has been operating since late 2024 and has targeted retail traders and cryptocurrency investors across 12 countries in 25 languages.
Imagine you're browsing the internet and you see an ad that looks like it's from a real company. But instead of just showing you the ad, the ad is actually making your computer build a special kind of software that can do bad things. This is what's happening in the SourTrade campaign, where the attackers are using a legitimate software called Bun to make your computer build the final executable. It's like a puzzle, and the attackers are using different pieces to make it hard for defenders to solve.
Analysis
A Malvertising Operation Like No Other
The SourTrade campaign is a unique example of a malvertising operation that uses a legitimate Bun runtime to make victims' browsers build the final Windows executable. This approach allows the attackers to evade detection by traditional security measures, making it a challenging threat for defenders to identify.
How It Works
The campaign begins with a landing page that fingerprint visitors, showing suspected researchers and bots an empty page while selected targets receive a convincing copy of the impersonated service. The defense against this is the ordinary one: install trading and wallet software from the vendor's own site, not from an ad.
The Role of Bun
Bun is a legitimate runtime that supports compiling applications and bytecode into standalone Windows executables. The attackers use Bun to build the final executable, making it difficult for defenders to identify the malicious activity. The use of Bun also allows the attackers to rotate the seed and size in each /config response, changing the hash while retaining the executable payload code.
The Importance of Examining the Whole Chain
Defenders should examine the whole chain, from the ad referral and cloaked landing page through the /config request, the secondary-domain runtime fetch, and the ServiceWorker download, rather than treating any single network or file artifact as decisive. This approach will help defenders to identify the malicious activity and prevent the attackers from evading detection.
Key points
- The SourTrade campaign is a unique example of a malvertising operation that uses a legitimate Bun runtime to make victims' browsers build the final Windows executable.
- The campaign has been operating since late 2024 and has targeted retail traders and cryptocurrency investors across 12 countries in 25 languages.
- The use of a legitimate Bun runtime to build the final executable makes it difficult for defenders to identify the malicious activity.
- Defenders should examine the whole chain, from the ad referral and cloaked landing page through the /config request, the secondary-domain runtime fetch, and the ServiceWorker download, rather than treating any single network or file artifact as decisive.
The SourTrade campaign highlights the importance of examining the whole chain of events, from the ad referral to the ServiceWorker download. By doing so, defenders can identify the malicious activity and prevent the attackers from evading detection. This approach will help to improve the security of the internet and prevent similar campaigns in the future.
The SourTrade campaign also highlights the limitations of traditional security measures. The use of a legitimate Bun runtime to build the final executable makes it difficult for defenders to identify the malicious activity. This approach allows the attackers to evade detection, making it a challenging threat for defenders to identify.



