SourTrade Delivers Bespoke, Browser-Assembled Malware

We must summon all our sympathy for the cryptocurrency traders who are getting hit by this one.

What’s Happening

Confiant reports on a novel malware delivery technique that assembles the payload in-browser using a ServiceWorker, a Bun runtime, and per-device config details.

They…neglected to mention what the malware does, but let’s assume given the space that it’s some flavor of infostealer.

Actions

Stop trading cryptocurrency. But also, the blog has a list of domains that are probably good to block.

Goodness poor Bun. Have become a favorite tool for threat actors.