mediumMalware

SourTrade Malvertising Campaign

First seen Jul 26, 2026 · Updated Jul 26, 2026

malvertisingwindowsfake-cryptosocial-engineeringevasionbun-runtimetrading-platforms

SourTrade is a malvertising campaign active since late 2024 that impersonates trusted brands like TradingView, Solana, and Luno to lure retail traders and crypto investors. It uniquely constructs its malicious Windows executable client-side, in the victim's browser, using a legitimate Bun JavaScript runtime as its base, avoiding detection by never serving a single complete malicious binary from a static URL.

Technical Analysis

The campaign leverages malicious advertising networks to redirect victims to spoofed pages mimicking TradingView, Solana, and Luno. Rather than hosting a complete malicious executable at a fixed URL (a common detection signature), SourTrade delivers the payload in fragmented pieces that are assembled and compiled into a final Windows executable directly within the victim's browser, using the legitimate Bun JavaScript runtime as a build base. This technique evades static file-hash detection, URL reputation blocking, and network-based signature scanning since no single request yields the complete malware. There is no direct evidence in current reporting that this campaign specifically targets AI agent infrastructure or credentials, but any host compromised by the resulting Windows executable that also runs local LLM tools, agent frameworks, or stores API keys/secrets in browser-accessible locations could have those credentials exfiltrated, warranting agent-relevant caution for organizations whose traders or engineers use agent-integrated trading tools on affected endpoints.

Affected Systems

Windows desktop/laptop systems belonging to retail traders and crypto investors who click on malicious ads impersonating TradingView, Solana, and Luno; browsers capable of executing JavaScript-based Bun runtime builds

Indicators of Compromise

  • Domains and infrastructure impersonating TradingView, Solana, and Luno (specific domains/hashes not disclosed in source data)
  • Malicious ad creatives referencing crypto trading platforms
  • Bun runtime-based build artifacts generated client-side

Remediation Steps

  1. 1

    Block malvertising domains

    Deploy ad-blocking and DNS filtering solutions to prevent access to known malicious ad networks and spoofed trading platform domains.

  2. 2

    Endpoint monitoring for anomalous builds

    Monitor endpoints for unexpected use of Bun runtime or unusual client-side compilation activity in browser processes.

  3. 3

    User awareness training

    Educate traders and crypto users to verify URLs and avoid downloading executables prompted by advertisements, even from seemingly legitimate trading platform ads.

  4. 4

    Application allowlisting

    Implement application control policies to prevent execution of unauthorized or unsigned Windows executables generated via browser-based build processes.

  5. 5

    Credential and API key hygiene

    Rotate and audit API keys and credentials on any endpoint suspected of compromise, particularly those used by trading bots or AI agent integrations.

Industries Most Exposed

financial servicescryptocurrencyretail tradingfintech

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.