
SourTrade Malvertising Campaign Targets Retail Traders Using Legitimate Bun Runtime
MalvertisingMalwareCybersecuritySocialEngineering
A malvertising campaign named SourTrade has been active since late 2024, delivering malware by forcing victims' browsers to assemble a Windows executable in pieces rather than downloading a complete malicious file. The attack leverages the legitimate Bun runtime as its foundation and impersonates platforms like TradingView, Solana, and Luno to target retail traders. Security firm Confiant disclosed details of the operation on July 23, 2026, highlighting its evasion tactics by avoiding direct payload delivery from a fixed URL. No specific malware families, CVE IDs, or infection statistics were provided in the reported findings.