The Bun runtime, a legitimate JavaScript runtime built on Apple's JavaScriptCore engine, is used by the SourTrade malvertising campaign as a base for assembling malware executables in the victim's browser. The browser retrieves a clean Bun runtime from a secondary domain, and attacker-controlled bytecode is inserted to create the final executable.