Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable Contact/Tip Us Reach out to get featured—contact us to send your exclusive story idea, research, hacks, or ask us a question or leave a comment/feedback! Follow Us On Social Media RSS Feeds Email Alerts Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable Swati Khandelwal Jul 25, 2026 Browser Security / Malvertising A malvertising operation dubbed SourTrade is making victims’ browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL. Confiant, which detailed the campaign on July 23, 2026, said it has operated since late 2024 and impersonated TradingView, Solana, and Luno to target retail traders and cryptocurrency investors across 12 countries in 25 languages. Its landing pages fingerprint visitors, showing suspected researchers and bots an empty page while selected targets receive a convincing copy of the impersonated service. The defense against that is the ordinary one: install trading and wallet software from the vendor’s own site, not from an ad. The documented chain does not rely on a browser vulnerability or remove Mark of the Web (MotW). Confiant’s analysis documents the delivery, not execution of the file inside the browser, and does not establish whether the final download starts automatically or requires a click. The landing page begins preparing the delivery path without waiting for a download click. It registers a page-scoped ServiceWorker at /sw.js , then builds a SharedWorker from JavaScript already embedded in the page, so the worker source never appears as a separate fetch. The SharedWorker requests /config , which returns a template, a secondary runtime URL, and session-specific random values. The browser retrieves and decompresses a clean Bun runtime from that second domain, purelogicbox[.]org in the published sample response. Base64 blobs in the configuration supply the Portable Executable (PE) header, section table, and a .bun section containing malicious JavaScriptCore bytecode for app.js . Bun runs on Apple’s JavaScriptCore engine and legitimately supports compiling applications and bytecode into standalone Windows executables. The worker then generates a large pseudorandom byte stream using AES in counter mode (AES-CTR). It then follows the supplied template as a byte-copy recipe, combining selected ranges from the Bun runtime, the generated stream, and the attacker-controlled executable material. Each victim can receive a different assembled file: rotating the seed and size in each /config response changes the hash while retaining the executable payload code. “No finished malware ever exists on the network,” wrote Michael Steele of Confiant’s threat intelligence team. No complete binary does, though the PE structures and the bytecode arrive as Base64 in /config . Once assembled, the page passes the executable to the ServiceWorker as a readable stream. A hidden iframe navigates to a same-origin URL, and the worker returns the generated bytes with a Content-Disposition attachment header. The resulting MotW record identifies the landing page as the download source, not the separate domain that supplied the Bun runtime. MotW itself remains present. The method evolved from activity Confiant tracked through April 30, 2026, when the pages loaded StreamSaver.js , an open-source streamed-download library, from its author’s GitHub Pages address. That left the recorded download path pointing at the library’s GitHub URL. The current pages keep its streaming architecture, including the streamsaver: message names, but no longer fetch it from GitHub. Bitdefender documented the related TradingView malvertising cluster in September 2025, identifying its final payload as the stealer Check Point tracks as JSCEAL and WithSecure as WeevilProxy . Confiant identifies shared campaign and executable characteristics but does not demonstrate that the three published samples carry that payload. The report also says Bitdefender found a modified Bun executable in this cluster. The Hacker News found no mention of Bun in the September 2025 post Confiant links to, which names its loader detection Variant.DenoSnoop.Marte.1. Credential theft, keylogging, traffic interception, wallet theft, and remote-access capabilities documented in the earlier campaign therefore cannot yet be assigned to the current files. The Hacker News has reached out to Confiant for clarification on its reference to Bitdefender’s earlier findings and will update this story with any response. There is no software patch to apply. The evasion is narrower than it first looks. Confiant’s own practical-implications section puts it more modestly: unique per-session builds limit the value of simple hash-based detections. The attacker-controlled PE material and bytecode still cross the network. Defenders should examine the whole chain, from the ad referral and cloaked landing page through the /config request, the secondary-domain runtime fetch, and the ServiceWorker download, rather than treating any single network or file artifact as decisive. Confiant published three SHA-256 hashes and a list of malicious domains, 96 by The Hacker News’ count. The firm named no actor and stopped its analysis at the moment the file lands on disk. Found this article interesting? Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post. SHARE Tweet Share Share Share Share on Facebook Share on Twitter Share on Linkedin Share on Reddit Share on Hacker News Share on Email Share on WhatsApp Share on Facebook Messenger Share on Telegram SHARE browser security , Cryptocurrency Security , Cybercrime , endpoint security , malvertising , Malware , Social Engineering , Threat Intelligence , Web Security , Windows Security ⚡ Top Stories This Week URGENT – Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 Meta Files Patent for AI That Can Listen All Day and Track How You’re Feeling New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code ⭐ Featured Resources What Security Teams Must Defend in the New AI Software Supply Chain Identity Fraud Is Changing Fast. See the Attacks Businesses Face in 2026 What 25 Million Alerts Reveal About the Threats SOCs Ignore How to Find and Control Every Script Running Through Your Marketing Stack Modern SASE Guide: Close the Gaps Traditional Network Security Cannot See Cybersecurity Webinars Risk in AI-Generated Code How to Secure AI Code Before It Reaches Production Learn how 300 enterprise leaders are managing AI-driven open-source risk, remediation debt, and governance at scale. Register Build AI Securely How to Secure AI-Built Software at Machine Speed Learn how to govern risk, secure AI-built software, and keep control as development moves at machine speed. Register ⚡ Latest News Cybersecurity Resources 5 Steps to Secure Against Software Vulnerabilities Discovered by AI Models AI has emerged as a potent weapon in cybersecurity. Learn how to best safeguard your organization. Get Ready for What’s Next in AI & Cloud Security Join practitioners tackling AI governance, cloud security, and autonomous systems. SANS SEC660 (GXPN): Write Exploits. Bypass Defenses. Own the Network. The most advanced SANS pentesting course is at Network Security 2026. Stephen Sims, live in person. Expert Insights Articles Videos The New Insider Has No Pulse: Securing Privilege When the Actor Is an AI Agent July 20, 2026 Read ➝ The Most Monitored Device in the Company is Still Hiding Dangerous Access July 20, 2026 Read ➝ AuthNContext and AMR, We Remember What MFA You Provided Last Summer! July 14, 2026 Read ➝ Breach Transparency Remains Cybersecurity’s Toughest Governance Problem July 6, 2026 Read ➝ Get the Latest News in Your Inbox Get the latest news, expert insights, exclusive resources, and strategies from industry leaders, all for free. Email


