hacker-news · Crawled Sep 7, 2026

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

3 IoCs 1 Malware
Read original article ↗

AI Summary

JSCeal is a compiled V8 JavaScript malware designed to steal browser credentials, cookies, and OAuth tokens, enabling attackers to bypass Google authentication via session replay attacks. It is distributed through malvertising campaigns, particularly the SourTrade operation, which impersonates legitimate cryptocurrency trading platforms like TradingView, Solana, and Luno. The malware uses heavy obfuscation techniques and in-memory assembly to avoid detection, and includes modules for keystroke logging, screenshot capture, and traffic interception via a local proxy targeting financial and cryptocurrency services.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 3 extracted

Type Value Detail
Domain tradingview[.]com Details →
Domain solana[.]com Details →
Domain luno[.]com Details →

MITRE ATT&CK TTPs 12 techniques