SourTrade malvertising campaign targeting retail traders and crypto investors
Campaign
Summary
Hide ▲
Show ▼
The SourTrade malvertising campaign now uses fake Solana, Luno, and TradingView pages with malicious JavaScript to assemble malware in browser memory, reducing detection and widening risk for retail traders and crypto investors. It has been active since late 2024 and operates across 25 languages in 12 countries, mainly in Asia Pacific and Latin America. The current delivery flow uses ServiceWorker and SharedWorker logic to build a unique payload locally and evade static detection.
Timeline
-
25.07.2026 18:21 2 articles · 1h ago
SourTrade delivers malware through fake trading pages and browser workers
Initial DisclosureConfiant describes SourTrade as a malvertising campaign that uses fake Solana, Luno, and TradingView pages with malicious JavaScript to make browsers assemble malware in memory for retail traders and crypto investors. The delivery chain registers a service worker, uses a shared worker and a '/config' assembly response to build the payload locally, rotates seed and size parameters to create a unique hash that bypasses static detection, and shifts from earlier StreamSaver delivery to same-origin ServiceWorker handling. The campaign is localized to 25 languages in 12 countries across Asia Pacific and Latin America.
Show sources
- Malicious sites use JavaScript to build malware in browser memory — www.bleepingcomputer.com — 25.07.2026 18:21
- Malicious sites use JavaScript to build malware in browser memory — www.bleepingcomputer.com — 25.07.2026 18:21