Malvertising Uses Browser to Build Malware Executable

Discover how SourTrade malvertising tricks browsers into assembling malware using Bun runtime. Targets traders on TradingView, Solana, Luno. Stay protected.

domingo, 26 de julio de 2026 • 4 min read • Q2BSTUDIO Team

Campaña SourTrade: malware fragmentado se ensambla en el navegador

The landscape of cyber threats is constantly evolving, and the latest trend in malvertising shows how attackers exploit legitimate technologies to evade detection. A campaign active since late 2024, internally known as SourTrade, has revolutionized the modus operandi by using the victim's web browser as a compilation platform. Instead of serving a complete executable from a fixed URL, attackers send code that, when executed in the browser, downloads the necessary components and uses the Bun runtime —a modern runtime for JavaScript and TypeScript— to build the malicious binary directly on the victim's machine. This approach greatly hinders detection by traditional security solutions, as there is no single malicious file to analyze; the compilation process occurs dynamically, mimicking legitimate behavior.

The campaign has primarily targeted retail traders, impersonating popular platforms like TradingView, Solana, and Luno through deceptive ads on networks and search engines. When users click these ads, they are redirected to pages that initiate the download of a script that, using Bun, builds a remote access Trojan (RAT) or an information stealer. The choice of Bun is no coincidence: this runtime, designed for speed and compatibility with the Node.js ecosystem, allows the code to run on multiple platforms without a traditional compiler, facilitating integration with the browser.

From a technical perspective, this technique represents a qualitative leap in browser-based malware. Previously, attacks were limited to downloading executable files or PowerShell scripts, but now the browser itself acts as a just-in-time compiler. This not only hampers static analysis but also allows the malware to adapt to the victim's operating system on the fly. For companies, especially those handling financial or critical data, this threat underscores the need to adopt multi-layered security strategies that include endpoint protection, behavioral analysis, and network segmentation.

In this context, organizations should seriously consider implementing advanced cybersecurity solutions. A proactive approach involves not only installing firewalls and antivirus but also integrating AI-based intrusion detection systems that can identify anomalous patterns in traffic and process behavior. Furthermore, developing custom applications with security by design becomes essential to prevent vulnerabilities that attackers could exploit. Q2BSTUDIO, as a software and technology development company, offers specialized cybersecurity services, including pentesting and security audits that help identify and fix gaps before they are exploited.

The SourTrade campaign also highlights the importance of artificial intelligence in modern cybersecurity. Traditional signature-based systems are ineffective against constantly mutating attacks. Therefore, more and more companies are turning to machine learning models that analyze user and process behavior to detect suspicious activities. Q2BSTUDIO integrates these capabilities into its solutions, offering specialized AI agents that monitor environments in real time and automatically respond to incidents. These agents can, for example, block unauthorized code execution in the browser or alert the security team when malicious compilation attempts are detected.

Another relevant vector is the cloud infrastructure. Attackers often host malware components on public cloud services like AWS or Azure, leveraging the reputation of these platforms to evade blacklists. Companies migrating their operations to the cloud must implement strict access controls, data encryption, and continuous instance monitoring. Q2BSTUDIO advises on the secure configuration of AWS and Azure cloud environments, ensuring that resources are not used as attack vectors. Likewise, Business Intelligence (BI) tools such as Power BI can be integrated to analyze security logs and generate real-time dashboards that facilitate decision-making.

The emergence of techniques like SourTrade demonstrates that cybersecurity is not a destination but a continuous process of adaptation. Companies that invest in custom applications developed with security standards, combined with artificial intelligence and robust cloud infrastructure, are better prepared to face these threats. Q2BSTUDIO, with its expertise in custom software development, AI, cybersecurity, and cloud, positions itself as a strategic ally for organizations looking to protect their digital assets in an increasingly hostile environment.

In conclusion, malvertising that uses the browser to construct malicious executables is a reminder that innovation also reaches the dark side of technology. To counteract it, a combination of advanced technology, solid processes, and specialized partners is required. It is not just about reacting to an attack, but anticipating it by designing resilient systems from the ground up. Investment in cybersecurity, AI, and cloud is not an expense but a strategic necessity for any company that wants to operate with confidence in the digital age.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.