#JSCEAL
My research blog about #JSCeal is finally out! It was quite a journey. I hope you will like it! research.checkpoint.com/2026/breakin... // #V8 #bytecode #malware #deobfuscation #BlackHatUSA2026
August 31, 2026 at 2:23 PM
🚨 Watch out as #JSCEAL malware is targeting millions through fake crypto app ads, draining wallets and stealing user data.

Details: hackread.com/jsceal-malwa...

#CyberSecurity #Malware #Crypto #Scam #Fraud
New JSCEAL Malware Targets Millions via Fake Crypto App Ads
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
August 4, 2025 at 4:01 PM
-New JSCEAL malware
-XWorm V6 is out
-Gunra ransomware gets a Linux variant
-Avast releases FunkSec ransomware decrypter
-Google P0 changes reporting rules
-Train maker sues security researchers
-Sploitlight macOS TCC vulnerability
-Sex toy leaks user emails
-Gen. Haugh joins VC space
July 30, 2025 at 8:30 AM
Trellix’s latest threat-hunting report traces state-backed phishing, the #DarkSword iPhone exploit kit, a Node.js-based crypto stealer, and poisoned Axios npm packages across five covert campaigns.

Listen/Read: hackread.com/trellix-dark...

#Cybersecurity #ThreatResearch #Malware #APT28
Trellix Report Details DarkSword, JSCeal, Axios npm Attack and APT28 Campaigns
DarkSword, JSCeal, Axios, Bitter APT, and APT28 campaigns reveal evolving tactics targeting iPhones, Southeast Asia, software supply chains, diplomatic organizations, and European governments.
hackread.com
September 14, 2026 at 2:06 PM
At #BlackHat2026, I’ll walk through the #JSCeal #malware case study and the static deobfuscation toolkit I built to recover readable code from the obfuscated #V8 compiled bytecode.
If you’ll be at #BlackHat, I’d be glad to see you there!
blackhat.com/us-26/briefi...
August 1, 2026 at 1:54 PM
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

huntaegis.com
September 8, 2026 at 8:29 AM
Hackers Use Facebook Ads to Spread JSCEAL Malware via Fake Cryptocurrency Trading Apps thehackernews.com/2025/07/hack... via @TheHackersNews
Hackers Use Facebook Ads to Spread JSCEAL Malware via Fake Cryptocurrency Trading Apps
Malware campaign using Facebook ads and fake crypto apps delivers JSCEAL, targeting credentials and wallets.
thehackernews.com
July 31, 2025 at 4:11 PM
Hackers Use #Facebook Ads to Spread JSCEAL Malware via Fake Cryptocurrency Trading Apps

Rsearchers are calling attention to an ongoing campaign that distributes fake #cryptocurrency trading #apps to deploy a compiled V8 #JavaScript malware called JSCEAL

#TechNews

thehackernews.com/2025/07/hack...
Hackers Use Facebook Ads to Spread JSCEAL Malware via Fake Cryptocurrency Trading Apps
Malware campaign using Facebook ads and fake crypto apps delivers JSCEAL, targeting credentials and wallets.
thehackernews.com
August 1, 2025 at 8:15 AM
Check Point's hasherezade details JSCeal & shares the jsc_deobfuscator toolkit. JSCeal is a sophisticated cryptocurrency-focused stealer with broader credential-theft, surveillance, & traffic-interception capabilities, delivered as compiled V8 bytecode. research.checkpoint.com/2026/breakin...
September 1, 2026 at 8:47 AM
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities.

"The payloads are pr…
#hackernews #news
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. "The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers," Check Point Research said in a
thehackernews.com
September 8, 2026 at 3:00 AM
Hackers Use Facebook Ads to Spread JSCEAL Malware via Fake Cryptocurrency Trading Apps
Cybersecurity researchers are calling attention to an ongoing campaign that distributes fake cryptocurrency trading apps to deploy a compiled V8 JavaScript (JSC) malware called JSCEAL that can capture data fro...
Link Preview
Visit the link for more information
thehackernews.com
July 30, 2025 at 5:55 PM
The attack chains have been found to adopt novel anti-analysis mechanisms that rely on script-based fingerprinting, before delivering the final JSC payload.

www.tsfactory.com/forums/blog/...

#cybersecurity #facebook
Hackers Use Facebook Ads to Spread JSCEAL Malware via Fake Cryptocurrency Trading Apps - Community
Cybersecurity researchers are calling attention to an ongoing campaign that distributes fake cryptocurrency trading apps to deploy a compiled V8 JavaScript (JSC) malware called JSCEAL that can capture...
www.tsfactory.com
July 31, 2025 at 1:28 PM
⚠️ New malware "JSCEAL" impersonates crypto apps (Binance, MetaMask) in a massive ad campaign, potentially affecting 10M+ users! Steals passwords, wallet data & more. Download apps ONLY from official sources & enable 2FA! More info: link to article - add a shortened link here
July 31, 2025 at 1:29 PM
⚠️ Crypto users! ⚠️ JSCEAL malware is spreading via fake ads for 50+ crypto trading apps, stealing credentials & wallet data. Active in EU since March '24. Download apps *only* from official sources! Low detection rates. #crypto #malware #security

#blockchain #news
July 31, 2025 at 5:27 AM
⚠️ New malware "JSCEAL" targets crypto users! ⚠️ Disguised as ads for Binance, MetaMask, Kraken & 50+ other platforms, it steals wallet info, logins, & more. Affecting 10M+ globally since March '24. Spread via ads on Facebook. Stay vigilant! #cybersecurity #crypto #malware

#blockchain #news
July 31, 2025 at 5:22 AM
Trellix Details DarkSword, JSCeal, Axios npm Attack and APT28 Campaigns hackread.com/trellix-dark...
Trellix Report Details DarkSword, JSCeal, Axios npm Attack and APT28 Campaigns
DarkSword, JSCeal, Axios, Bitter APT, and APT28 campaigns reveal evolving tactics targeting iPhones, Southeast Asia, software supply chains, diplomatic organizations, and European governments.
hackread.com
September 16, 2026 at 9:12 PM
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 56

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Endgame Gear mouse config tool infected users with malware Auto-Color Backdoor: H…

#hackernews #news
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 56
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Endgame Gear mouse config tool infected users with malware Auto-Color Backdoor: How Darktrace Thwarted a Stealthy Linux Intrusion  Sealed Chain of Deception: Actors leveraging Node.JS to Launch JSCeal Decrypted: FunkSec Ransomware  Threat actor uses […]
securityaffairs.com
August 4, 2025 at 11:49 AM
📚 SOURCES: BleepingComputer (BigBear 2.0), TheHackerNews (Chrome 0-day CVE-2026-85046), Huntress (N-central CVE-2026-86218), TheHackerNews (JSCeal malware session cookie theft), CISA KEV catalog. #InfoSec
September 10, 2026 at 6:01 AM
New infostealer JSCeal uses compiled V8 JavaScript to steal session cookies and bypass Google authentication — no password needed… https://0daynews.com/articles/2026-09-07-jsceal-malware-google-auth-bypass/?utm_source=bluesky&utm_medium=organic_social&utm_campaign=always_on&utm_content=hub-1284
September 9, 2026 at 12:30 PM
JSCeal is compiled V8 JS malware that harvests credentials and intercepts traffic. It bypasses Google auth using stolen session… https://0daynews.com/articles/2026-09-07-jsceal-malware-google-auth-bypass/?utm_source=bluesky&utm_medium=organic_social&utm_campaign=always_on&utm_content=hub-1283
September 9, 2026 at 11:15 AM
📚 SOURCES: BleepingComputer (BigBear 2.0), TheHackerNews (Chrome 0-day CVE-2026-85046), Huntress (N-central CVE-2026-86218), TheHackerNews (JSCeal malware session cookie theft), CISA KEV catalog. #InfoSec
September 9, 2026 at 4:03 AM
JSCeal Hides Crypto Malware in V8 Bytecode

JSCeal hides crypto-stealing malware in V8 bytecode, but researchers built a tool to decompile it and expose its advanced theft capabilities. JSCeal is a cryptocurrency stealer that Check Point Research has tracked since early 2025. Unli…
#hackernews #news
JSCeal Hides Crypto Malware in V8 Bytecode
JSCeal hides crypto-stealing malware in V8 bytecode, but researchers built a tool to decompile it and expose its advanced theft capabilities. JSCeal is a cryptocurrency stealer that Check Point Research has tracked since early 2025. Unlike most malware, it hides its code in a format that makes analysis much harder. Check Point presented its latest […]
securityaffairs.com
September 8, 2026 at 9:07 AM
Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities.

thehackernews.com/2026/09/jsce...
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
JSCeal can steal browser credentials, replay Google sessions using stolen cookies, and modify traffic for cryptocurrency services.
thehackernews.com
September 8, 2026 at 6:02 AM
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies: thehackernews.com/2026/09/jsce...
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
JSCeal can steal browser credentials, replay Google sessions using stolen cookies, and modify traffic for cryptocurrency services.
thehackernews.com
September 7, 2026 at 10:58 PM