Bun: JavaScript Runtime Used in Malware Payload
Bun is a JavaScript runtime that the worm's stage one downloads (version 1.3.13) to execute a compiled credential-stealing bundle.
Bun is a JavaScript runtime that the worm's stage one downloads (version 1.3.13) to execute a compiled credential-stealing bundle.
The Bun runtime, a legitimate JavaScript runtime built on Apple's JavaScriptCore engine, is used by the SourTrade malvertising campaign as a base…
The phishing campaign downloads a legitimate Node.js v24.13.0 runtime from nodejs.org to execute the TonRAT implant in user space.