A new malicious advertising campaign named SourTrade shows how web attacks can move from downloading a complete malware file to a split-and-assemble model inside the victim's browser. According to The Hacker News, the campaign impersonates familiar trading and cryptocurrency brands such as TradingView, Solana and Luno to lure users to purpose-built websites.
The notable point is that the malicious page does not simply serve a Windows executable from a fixed path. Instead, JavaScript on the page uses Web Worker and Blob mechanisms to stitch code fragments together, then drops the next-stage file for the victim to run. This gives the campaign more room to evade static detection based on a single file or URL.

How SourTrade evades traditional detection
In many earlier malvertising campaigns, defenders could rely on download URLs, file hashes or executable patterns for early blocking. SourTrade makes that harder because the final file can be generated per session, while its components are scattered across web logic and legitimate resources. If defenders inspect only one download path, they can miss the critical part of the attack chain.
The abuse of the Bun runtime also adds meaningful noise. Bun is a legitimate tool in the JavaScript ecosystem, so its presence is not automatically malicious. When attackers use a legitimate runtime to support later execution, security teams need to correlate website behavior, process creation, command lines and network connections instead of looking only for one suspicious binary.
Cryptocurrency users remain attractive targets
The brands impersonated in the campaign show that the operators are targeting users connected to investing, trading and cryptocurrency wallets. This is a group with a high likelihood of holding directly monetizable assets, and many are used to installing tools, extensions or trading utilities from online prompts.
The Hacker News cites Confiant's analysis that the campaign has been active since late 2024 and shows signs of expanding across multiple countries. That indicates SourTrade is not merely a small test, but an operation with enough persistence to adjust distribution infrastructure and keep pursuing victims through malvertising channels.
Organizations should monitor behavior chains, not just downloaded files
For organizations, the main lesson is not to treat the browser as a fully passive zone. When websites can orchestrate workers, create blobs, download fragments and trigger execution flows, monitoring needs to cover the full chain from ad click to landing page, script behavior, file creation and process execution.
Security teams should also review download policies from advertising traffic, limit execution rights in user directories, enable application control and train users to avoid installing tools from promotional pages. For groups handling cryptocurrency assets, dedicated browser profiles, hardware wallets and strict software allow lists can reduce exposure.
Why this incident matters
SourTrade is not the first campaign to use fake pages to spread malware, but it reflects a concerning trend: browser-side attacks are increasingly using modern web technology itself to blur the line between legitimate content and malicious payloads. When malware is assembled dynamically per session, sharing a single hash or block URL becomes less effective.
As users rely more heavily on web applications, digital wallets and online trading tools, campaigns such as SourTrade reinforce a core principle: security is not only about patching software, but also about observing the full journey from advertisement, landing page and JavaScript behavior through to processes running on the user's machine.
VNCyberS compiled from The Hacker News, BleepingComputer and Confiant















