JSCeal Malware Hijacks Google Accounts via Stolen Browser Cookies — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Check Point Research published a technical breakdown of JSCeal, a compiled V8 JavaScript malware with credential harvesting, surveillance, and traffic-interception capabilities, protected by javascript-obfuscator using RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers.
- JSCeal was first documented in July 2025 and spreads through fake cryptocurrency trading sites reached via malicious ads on Facebook and Google, tricking users into downloading bogus TradingView installers; the activity overlaps with threat clusters tracked as WEEVILPROXY and MeadowLocust.
- Ad security platform Confiant disclosed a parallel malvertising operation codenamed SourTrade that impersonates Solana, Luno, and TradingView and has been active since late 2024, targeting retail traders and crypto investors across 12 countries in 25 languages, primarily in Asia Pacific and Latin America.
- SourTrade is technically distinct because its landing page delivers assembly instructions to the victim's browser, retrieves a clean legitimate file from separate infrastructure, and builds the final malware in memory — meaning no finished malware ever exists on the network.
- JSCeal's browser-stealing module enumerates user-data directories for Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Avast Secure Browser, Vivaldi, and Cốc Cốc, extracting saved cookies, passwords, and OAuth tokens from available profiles.
- The malware leverages stolen cookie data to reconstruct browser sessions and conduct active session replay attacks that bypass authentication to gain unauthorized access to victims' Google accounts, with a second module providing keystroke recording and surveillance capabilities.
- A proxy module within JSCeal installs custom certificates and includes service-specific handlers that modify requests and responses for Binance, Bybit, and Ledger, capturing account data and cryptocurrency balances from active trading sessions.
- Check Point researcher Aleksandra "Hasherezade" Doniec said the version-specific compiled V8 format combined with pre-compilation obfuscation "moves [the malware] outside the workflows that analysts normally rely on," indicating JSCeal remains under active development.
Why it matters: Retail cryptocurrency investors across 12 countries face an escalating threat that combines cookie theft, Google account hijacking, and real-time interception of trading traffic on Binance, Bybit, and Ledger. SourTrade's in-memory assembly technique means no finished malware exists on the network for traditional security tools to detect, making the campaign harder to block at the endpoint level.
Ask SkimNews




