JSCeal Malware Bypasses Google Auth via Stolen Cookies — SkimNews

Get the Geopolitics newsletter
Daily geopolitics — wars, elections, sanctions, the diplomatic moves that move markets. Free.
- Check Point Research published a technical report on JSCeal, a compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities, protected by javascript-obfuscator using RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers.
- JSCeal was first documented by Check Point in July 2025, distributed via fake cryptocurrency trading sites pushed through malicious ads on Facebook and Google, with bogus TradingView installers deploying the payload to victims.
- SourTrade, a related malvertising operation disclosed by ad security firm Confiant last month, has been active since late 2024 targeting retail traders and crypto investors across 12 countries in 25 languages, primarily in Asia Pacific and Latin America.
- SourTrade's technically distinct method: it never distributes finished malware, instead delivering assembly instructions to the victim's browser, retrieving a clean legitimate file, and building the final malware in memory.
- JSCeal's browser-stealing module targets Chromium-based browsers including Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Avast Secure Browser, Vivaldi, and Cốc Cốc, extracting cookies and passwords to enable session replay attacks that bypass authentication on victims' Google accounts.
- JSCeal embeds a local proxy module with dedicated handlers for Binance, Bybit, and Ledger, plus service-specific request and response modification, alongside keystroke recording and screenshot surveillance capabilities.
Why it matters: Retail crypto traders across 12 countries face a malware strain that doesn't just steal passwords but reconstructs active browser sessions to bypass two-factor authentication entirely, meaning even security-conscious Google account holders can be silently hijacked. The in-memory build technique means traditional network-based malware scanning cannot detect the final payload before execution.
Ask SkimNews




