Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

July 25, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Retail cryptocurrency traders and investors
Incident: A malvertising campaign dubbed SourTrade delivers malware by assembling the final executable within the victim’s browser.
Impact: Victims may unknowingly download and execute stealthy malware designed to steal financial assets or credentials.
Attacker: Unidentified threat actors
Analysis: The SourTrade campaign leverages a legitimate Bun runtime and a complex chain of ServiceWorkers to assemble a Windows executable client-side. By combining Base64 blobs with a clean runtime, the attackers create unique file hashes for every victim, effectively defeating signature-based detection. The operation uses sophisticated cloaking to hide from researchers while targeting cryptocurrency investors via impersonated trading platforms.
Recommendations: Download financial and wallet software exclusively from official vendor websites.; Implement robust DNS filtering to block known malicious delivery and configuration domains.; Monitor for suspicious ServiceWorker registrations and unexpected executable downloads originating from browser sessions.
Source: The Hacker News / Confiant

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *