Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Mladic’s funeral: Were no lessons learned? | Crimes Against Humanity

    September 8, 2026

    Whispering Complaints Into Your Phone May Be the Future of Customer Feedback

    September 8, 2026

    JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

    September 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Mladic’s funeral: Were no lessons learned? | Crimes Against Humanity
    • Whispering Complaints Into Your Phone May Be the Future of Customer Feedback
    • JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
    • OpenAI Chief Scientist Warns AI Labs May Need to Slow Down
    • Friedrich Merz is now on borrowed time. But that’s not why the AfD’s triumph is seismic | Jörg Lau
    • Indonesia airports reopen after volcano eruption leaves 340,000 stranded
    • First Xiaomi, then the world: why Arm might give phone gaming a huge graphics boost
    • Reducto Releases r-1: A Single Pass Document Parsing Model That Cuts Errors 20% at 1 Cent Per Page
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 8
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 8, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities.

    “The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers,” Check Point Research said in a technical report published last week.

    JSCeal was first documented by Check Point in July 2025, highlighting the threat actors’ use of fake cryptocurrency trading sites to which unsuspecting users are redirected via malicious ads on Facebook and Google. The counterfeit sites instruct them to download bogus installers for TradingView that lead to the deployment of the malware. The activity overlaps with a threat cluster tracked under the monikers WEEVILPROXY and MeadowLocust.

    Malvertising campaigns distributing the malware make use of two ZIP archives delivered via PowerShell: one containing the Node.js runtime and the other containing the main payload and other auxiliary components.

    As recently as last month, ad security platform Confiant disclosed details of a massive malvertising operation codenamed SourTrade, which has been observed impersonating trusted trading and cryptocurrency brands, such as Solana, Luno, and TradingView, to serve lookalike portals with malicious JavaScript that instructs web browsers to assemble malware directly in memory.

    The campaign is assessed to be active since late 2024, targeting retail traders and cryptocurrency investors across 12 countries in 25 languages, primarily in Asia Pacific and Latin America. Evidence indicates that the campaign overlaps with a JSCeal campaign described by Bitdefender in September 2025.

    Cybersecurity

    “What makes SourTrade technically distinct is what happens on its landing page,” Confiant said. “It does not distribute finished malware. Instead, it delivers assembly instructions to the victim’s browser, retrieves a clean legitimate file from separate infrastructure, and directs the browser to build the final malware in memory on the victim’s machine. No finished malware ever exists on the network.”

    JSCeal is protected using javascript-obfuscator, with the operators repeatedly using four groups of transformations to obscure the malware. These include –

    • Replacing function and variable names with short or nonsensical identifiers
    • Splitting important strings into chunks (which are subsequently encoded and RC4-protected) and then reconstructing them through decoder functions
    • Using control-flow flattening to turn program flow into a flat, single-level switch statement controlled by an infinite loop and a state variable with the goal of making analysis and reverse‑engineering harder
    • Forwarding function calls through proxy helpers and wrapping simple operations, like addition, subtraction, comparison, or function invocation, in dedicated helper functions

    The Israeli cybersecurity company said it developed a “fully static deobfuscation pipeline” to decode compiled V8 JavaScript bytecode protected with the utility, thereby offering insights into the malware’s execution flow and its features, counting its ability to enumerate installed browsers, and query saved secrets, cookies, OAuth tokens, and other data from them, as well as “router” functions that register handlers for the collected information.

    The browser stealing module targets a long list of Chromium-based browsers, such as Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Avast Secure Browser, Vivaldi, and Cốc Cốc. For each browser, the malware navigates to the expected location of its user-data directory and lists available profiles, from where cookies and passwords are extracted.

    What’s more, JSCeal is equipped to leverage the stolen cookie data to reconstruct a browser session and conduct active session replay attacks to bypass authentication and gain unauthorized access to a victim’s Google account. A second module embedded within the malware offers surveillance capabilities by recording keystrokes and taking screenshots.

    Cybersecurity

    “A common technique used by banking trojans is to install a local proxy and inject or modify web content in selected services,” Check Point said. “JSCeal follows a similar pattern: the recovered code shows proxy setup, certificate generation and installation, and service-specific request and response modification.”

    “The proxy is not limited to passive interception. The recovered code contains dedicated handlers that modify selected requests and responses for specific services. A configuration function exposes separate overrides for Binance, Bybit, and Ledger, as well as generic handlers for replacing HTML, blocking hosts, and clearing selected cookies.”

    There also exist multiple handlers specifically focused on cryptocurrency platforms, one of which captures account data and records cryptocurrency balances.

    “JSCeal combines two forms of analysis friction: a version-specific compiled V8 format and several layers of JavaScript obfuscation applied before compilation. Neither makes the malware impossible to reverse, but together they move it outside the workflows that analysts normally rely on,” security researcher Aleksandra “Hasherezade” Doniec said.

    “Taken together, these developments show that the JSCeal authors are investing both in making the payload harder to analyze and in broadening its platform coverage. With campaigns continuing into recent months, the changes indicate that JSCeal remains under active development.”

    Authentication Bypass cookies Google JSCeal Malware Session stolen
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    OpenAI Agents Hijack Another Victim Website

    N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

    Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

    ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

    PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

    Hackers exploit new MikroTik RouterOS flaws to hijack routers

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Mladic’s funeral: Were no lessons learned? | Crimes Against Humanity

    September 8, 2026

    Whispering Complaints Into Your Phone May Be the Future of Customer Feedback

    September 8, 2026

    JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

    September 8, 2026

    OpenAI Chief Scientist Warns AI Labs May Need to Slow Down

    September 8, 2026
    Latest Posts

    Book Review: ‘Pure Men’ by Mohamed Mbougar Sarr

    August 1, 2026

    Bitcoin ETFs Post First Monthly Inflow Since April

    August 1, 2026

    Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

    August 1, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Mladic’s funeral: Were no lessons learned? | Crimes Against Humanity

    September 8, 2026

    Whispering Complaints Into Your Phone May Be the Future of Customer Feedback

    September 8, 2026

    JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

    September 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.