JSCeal: Malware Crafts In-Browser Sessions to Bypass Google Login

TL;DR Summary
Security researchers describe JSCeal, a sophisticated compiled V8 JavaScript malware that harvests credentials, keystrokes, and screenshots, and can reconstruct stolen cookies to replay browser sessions and bypass Google authentication. It uses multi‑layer obfuscation and a proxy-based traffic interceptor to modify requests for crypto services, and is delivered via malvertising campaigns (including SourTrade) that assemble the final payload inside the victim’s browser, signaling active development and broad targeting of Chromium-based browsers across 12 countries in 25 languages.
- JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies The Hacker News
- JSCeal Hides Crypto Malware in V8 Bytecode Security Affairs
- JSCeal Infostealer Malware Bypasses Google Authentication and 2FA via Stolen Browser Session Cookies Rescana
- JSCeal Crypto Stealer Uses V8 Bytecode to Steal Browser Credentials and Intercept HTTPS gbhackers.com
Reading Insights
Total Reads
1
Unique Readers
17
Time Saved
4 min
vs 4 min read
Condensed
90%
789 → 76 words
Want the full story? Read the original article
Read on The Hacker News