Security2 publishers2 min readPublished
Check Point's deobfuscation of 23 compiled V8 bytecode samples shows JSCeal replaying stolen cookies inside the victim's own browser profile, then stuffing local credentials at any password prompt until it holds a fresh OAuth token.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Cookies come out of each Chromium profile's user-data directory, one profile at a time [6]. They go back into a browser the malware starts on the same host, and the automation is written to avoid looking like a bot while it walks Google's own authentication flow [9]. If Google asks for a password, the malware tries every credential it already lifted from that machine until one is accepted, and the run ends with a fresh, valid OAuth token [10]. Check Point describes the same behaviour as active session replay to gain unauthorized access to a victim's Google account [11].
Check Point's recovered flow describes a password prompt and credential stuffing, with no second factor challenged [10]. The published evidence supports authentication bypass by session replay [11], and the artifact left behind is a token [10]. Whether MFA was enforced on the targeted accounts, and beaten, is not something the evidence establishes either way. Credential rotation that does not also revoke sessions and third-party grants leaves that access standing.
The naming needs care. JSCeal, WEEVILPROXY and MeadowLocust are one thing under three vendor labels [1], and Confiant's SourTrade overlaps a JSCeal campaign Bitdefender wrote up in September 2025 [17]. Four labels sit on one cluster [19], the work of one operation rather than four crews independently arriving at cookie theft. Dated reporting places the same activity in 2024, 2025 and 2026 [20]. SourTrade's contribution is on the delivery side: according to Confiant, the landing page hands the browser assembly instructions, pulls a clean legitimate file from separate infrastructure, and has the browser build the payload in memory, so no finished malware ever exists on the network [18].
The service-specific handlers are where money moves. A configuration function exposes separate overrides for Binance, Bybit and Ledger, plus generic handlers for replacing HTML, blocking hosts and clearing cookies [8]. In practice that means the Binance login QR code swapped, a fake security challenge injected on Bybit, and Ledger's own scripts replaced with attacker-controlled content [7].
The analysis cost is lopsided. Two obfuscation layers, both assembled from existing open-source components, were cheap to produce and expensive to unwind, per the Security Affairs account of the report [14]. The answer was a purpose-built pipeline on top of the open-source View8 decompiler, which recovered readable code from 23 of 23 samples, a 100 percent hit rate [12][21]. Two things in this chain remain cheap to hunt for on a host: an attacker-generated certificate in the local trust store [5], and a Node.js runtime unzipped by PowerShell into a user directory [4]. Both land before the token does.
Ranked by verification strength, evidence, and original report placement.
JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications; other vendors tag it WEEVILPROXY or MeadowLocust.
JSCeal steals saved passwords and cookies from eight Chromium-based browsers, harvests Telegram session data, logs keystrokes, takes screenshots, and installs a locally generated attacker-controlled certificate to intercept and modify HTTPS traffic in transit.
The browser stealing module targets Chrome, Edge, Brave, Opera, Opera GX, Avast Secure Browser, Vivaldi and Coc Coc; for each it navigates to the expected user-data directory, lists available profiles, and extracts cookies and passwords.
The HTTPS interception capability lets JSCeal rewrite what a victim sees from real financial platforms, swapping login QR codes on Binance, injecting fake security challenges on Bybit, and replacing legitimate scripts served by Ledger's own website with attacker-controlled content.
Check Point: a configuration function exposes separate overrides for Binance, Bybit and Ledger, as well as generic handlers for replacing HTML, blocking hosts and clearing selected cookies.
The malware can launch a victim's own installed browser, inject stolen session cookies, and navigate through Google's actual account authentication flow using automation tooling built specifically to avoid looking like a bot.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor report, read twice
Almost every technical particular here traces to a single Check Point document: the eight browsers, the Binance QR swap, the per-service overrides, the 23 samples. It holds up better than most single-source security reporting because it is checkable in kind, with a sample count, a payload hash dated 11 November 2025, and named configuration handlers rather than adjectives. What it lacks is a second reader: no other lab has reproduced the recovery, and Confiant's claimed overlap with a Bitdefender campaign is stated without a shared indicator behind it.
Live campaigns, unmeasured victims
Deployment is documented but never sized. Dated activity runs from late 2024 through samples still appearing in 2026, and the malware has kept moving, adding an externally keyed AES layer and macOS support after the research began. Against that, the only quantities anyone offers describe operator reach rather than effect: 12 countries and 25 languages from Confiant, 23 samples from Check Point. No infection count, no confirmed hijacked account, no exchange losses.
Static capability, live-sounding headline
Both headlines promise Google authentication being bypassed; the basis is code paths read out of statically recovered bytecode, not a hijacked account anyone has documented. The gap stays small because the modal verb survives into the text and Hasherezade's quote in The Hacker News pushes the other way, calling the obfuscation an increase in analyst cost rather than a wall. Security Affairs pulls further in the honest direction by reporting where the recovery method already fails once the AES key sits outside the bundle.
Conference-season vendor research
The research arrives at Black Hat with a named pipeline, an AI assist and a decompiler extension attached to it, which is reputational work as much as threat intelligence. The second vendor, Confiant, sells ad-supply-chain inspection and its contribution is a malvertising operation. Both publishers relay long verbatim quotes and neither adds independent checking, and the same Hacker News text reaching us twice inflates how much coverage this looks like without adding a second reading.
Solid on mechanics, thin on scale
How this malware is packaged, obfuscated and pulled apart again is described precisely enough for a defender to act on, and Security Affairs and The Hacker News agree wherever they overlap. What holds us below high confidence is that the agreement is inherited from one Check Point document, that the account-takeover chain is read out of recovered code rather than seen happening to a victim, and that each publisher's gaps fall on the other's strong ground, so nowhere does a reader get the campaign picture and the malware internals together.
build
AmnesiaStealer drives your own browser, so session theft is the real macOS loss1 publisher
security
Chrome 152 ships 327 fixes and ten criticals, and the restart is the only one that counts2 publishers
invest
Copilot built the fake Ledger app. A human still only made 20 lookups in two weeks.1 publisher
security
Washington names industrial-scale distillation, then hands the detection bill to abuse teams1 publisher
Publishers with included, body-backed reporting in this cluster.
1 article · September 7, 2026
2 articles · September 7, 2026