< Back to all clusters
[TECHNOLOGY] · 4 sources

SourTrade Malvertising Campaign Steals Crypto Wallets via Browser Attack

Security researchers have identified the SourTrade malvertising operation, active since late 2024, which targets cryptocurrency investors with fake advertisements that mimic popular platforms such as Solana, Luno and TradingView. The campaign runs across regions including Asia‑Pacific, Latin America, Africa, Australia and Great Britain, luring users to compromised web pages.

The attackers employ a file‑less technique: JavaScript registers a ServiceWorker and a SharedWorker, then uses the Bun runtime to assemble a malicious Windows executable entirely in the browser’s memory. This approach evades traditional signature‑based detection. The resulting payload can act as a proxy, log keystrokes, and harvest credentials, focusing on stealing private keys and access to crypto wallets. The findings were reported by Confiant and BleepingComputer.