threat_intelligence302 wordsRead on Arc Codex

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

490/69 Tuesday, September 8, 2026 Cybersecurity researchers have disclosed the discovery of JSCeal, an infostealer malware strain developed to target general users, particularly retail investors and cryptocurrency traders in the Asia-Pacific and Latin America regions. The malware is distributed through malvertising campaigns on social media platforms such as Facebook and Google, luring users to fake digital asset trading websites and tricking them into downloading installers for simulated investment applications, such as TradingView. JSCeal has evolved to steal sensitive information, intercept network traffic, and capture keystrokes and screenshots, directly affecting users of Chromium-based browsers such as Google Chrome, Microsoft Edge, and Brave. Analysis of its operation found that the malware delivers two compressed files through PowerShell. The first contains the Node.js runtime used to execute the malware environment, while the second contains core components such as app.jsc for processing commands. The malware searches user data directories in web browsers to extract cookies, passwords, and saved OAuth tokens. It then uses the stolen cookie data to reconstruct session cookies, allowing attackers to impersonate users and access Google accounts without going through the normal authentication process. In addition, JSCeal installs a local proxy on the infected machine to intercept and modify web content on major cryptocurrency wallet and exchange services, such as Binance, Bybit, and Ledger. It also uses complex code obfuscation to hinder detection by antivirus software. To reduce the risk of falling victim to this threat, users should be cautious when clicking investment-related advertisements and download software only from official provider websites. Administrators and general users should enable multi-factor authentication (MFA) using authenticator applications or security keys, and regularly review the list of devices signed in to their accounts. If malware infection is suspected, users should immediately sign out from all devices, revoke existing sessions, and reset passwords for critical accounts. Source: https://thehackernews.com/2026/09/jsceal-malware-can-bypass-google.html

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.