Find notable cyber news and cases, enriched with sources, timelines, and signals.

SourTrade malvertising campaign targeting retail traders and crypto investors

Campaign
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

The SourTrade malvertising campaign now uses fake Solana, Luno, and TradingView pages with malicious JavaScript to assemble malware in browser memory, reducing detection and widening risk for retail traders and crypto investors. It has been active since late 2024 and operates across 25 languages in 12 countries, mainly in Asia Pacific and Latin America. The current delivery flow uses ServiceWorker and SharedWorker logic to build a unique payload locally and evade static detection.

Timeline

  1. 25.07.2026 18:21 2 articles · 1h ago

    SourTrade delivers malware through fake trading pages and browser workers

    Initial Disclosure

    Confiant describes SourTrade as a malvertising campaign that uses fake Solana, Luno, and TradingView pages with malicious JavaScript to make browsers assemble malware in memory for retail traders and crypto investors. The delivery chain registers a service worker, uses a shared worker and a '/config' assembly response to build the payload locally, rotates seed and size parameters to create a unique hash that bypasses static detection, and shifts from earlier StreamSaver delivery to same-origin ServiceWorker handling. The campaign is localized to 25 languages in 12 countries across Asia Pacific and Latin America.

    Show sources