JSCeal: Malware Crafts In-Browser Sessions to Bypass Google Login

1 min read
Source: The Hacker News
JSCeal: Malware Crafts In-Browser Sessions to Bypass Google Login
Photo: The Hacker News
TL;DR Summary

Security researchers describe JSCeal, a sophisticated compiled V8 JavaScript malware that harvests credentials, keystrokes, and screenshots, and can reconstruct stolen cookies to replay browser sessions and bypass Google authentication. It uses multi‑layer obfuscation and a proxy-based traffic interceptor to modify requests for crypto services, and is delivered via malvertising campaigns (including SourTrade) that assemble the final payload inside the victim’s browser, signaling active development and broad targeting of Chromium-based browsers across 12 countries in 25 languages.

Share this article

Reading Insights

Total Reads

1

Unique Readers

17

Time Saved

4 min

vs 4 min read

Condensed

90%

78976 words

Want the full story? Read the original article

Read on The Hacker News