HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Malvertising Campaign “SourTrade” Assembles Malware in the Browser Using Bun Runtime

SourTrade has been serving fragmented Windows payloads that browsers stitch together via the legitimate Bun runtime, impersonating trading platforms to target retail traders. The technique highlights the need for SOC 2‑aligned controls around web content filtering and security‑awareness training.

LiveThreat™ Intelligence · 📅 July 26, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
1 recommended
📰
Source
thehackernews.com

Malvertising Campaign “SourTrade” Assembles Malware in the Browser Using Bun Runtime

What Happened — The “SourTrade” malvertising operation has been delivering fragmented Windows payloads to browsers, which then re‑assemble the final executable using the legitimate Bun JavaScript runtime. The campaign, active since late‑2024, masquerades as trusted sites such as TradingView, Solana and Luno to target retail traders.

Why It Matters for Compliance & Audit Readiness

  • The attack exploits the same trust assumptions that SOC 2’s Security principle expects organizations to document and mitigate (e.g., controls over third‑party content and user‑device hygiene).
  • Continuous evidence of web‑filtering, endpoint detection, and security‑awareness training is essential to demonstrate that the organization can detect and respond to evolving malicious‑ad techniques.

Who Is Affected – Retail‑trading platforms, fintech SaaS providers, and any organization whose users browse the open web from corporate devices.

Recommended Actions

  • Map the incident to SOC 2 CC6.1 (Logical Access Controls) and CC7.1 (System Operations) to ensure controls cover malicious‑ad content.
  • Deploy or tighten web‑content filtering and endpoint protection that can detect fragmented payload assembly.
  • Refresh security‑awareness training to include malvertising detection and safe‑browsing practices.

Source: The Hacker News – Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

Technical Notes – The campaign uses legitimate Bun runtime (a JavaScript/TypeScript engine) as a delivery vehicle, avoiding static signatures. No specific CVE is cited; the threat relies on browser execution of remote script fragments. Data exfiltration potential is high once the assembled malware gains foothold.

📰 Original Source
https://thehackernews.com/2026/07/malvertising-sends-malware-in-pieces.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →