thehackernews.com 7 Sept 2026, 07:53 UTC

JSCeal Malware Hijacks Browser Sessions to Bypass Google Logins

RESEARCHERS have detailed JSCeal, a sophisticated compiled V8 JavaScript malware that collects credentials and monitors user activity, with the ability to replay a browser session to bypass authentication such as Google accounts. The malware’s payloads are protected by javascript-obfuscator and employ multiple techniques, including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers, making analysis challenging.

Check Point Research notes that JSCeal can enumerate installed Chromium-based browsers, locate each user-data directory, list profiles, and exfiltrate cookies, passwords and OAuth tokens, as well as other data stored by the browsers. A key capability is using stolen cookies to reconstruct an active browser session to bypass login requirements, enabling unauthorized access to a victim’s Google account. A second module provides keylogging and screenshot capture.

The operators reportedly target a broad range of Chromium-based browsers such as Chrome, Edge, Brave, Opera, Opera GX, Avast Secure Browser, Vivaldi, and Cốc Cốc, extracting cookies and saved secrets from each, then using a local proxy to modify requests and responses in targeted services. Check Point describes additional handlers that can override content for platforms including Binance, Bybit and Ledger, and even block hosts or clear cookies.

The campaign is linked to malvertising and past activity around SourTrade, which assembles malware in memory rather than delivering a finished payload. JSCeal has been associated with clusters known as WEEVILPROXY and MeadowLocust and appears to remain under active development, with campaigns dating from late 2024 across multiple countries and languages.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline