JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
- ID
- 22070
- Status
- summarized
- Published
- 07 Sep 2026, 3:53 PM
- Fetched
- 07 Sep 2026, 6:38 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/jsceal-malware-can-bypass-google.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 4.5
- Created
- 07 Sep 2026, 6:39 PM
- Tags
- Audience
- developerssaas_founders
What happened
Check Point Research detailed JSCeal, a compiled V8 JavaScript malware that steals session cookies to bypass Google authentication, distributed via fake crypto trading sites impersonating brands like TradingView, Solana, and Luno. A related Confiant-documented campaign called SourTrade, active since late 2024, delivers assembly instructions to the victim's browser so the malware is built in-memory rather than transmitted as a finished file, targeting retail traders across 12 countries in APAC and Latin America.
Why it matters
If you build fintech, crypto, or trading products targeting APAC retail users, your users are actively being phished via lookalike ads impersonating brands like Luno and TradingView — consider user education and brand-monitoring for malvertising impersonation. The in-browser malware assembly technique means traditional network-based AV won't catch the payload, which matters if you rely on endpoint or network filtering for your team's devices.
Discussion angle
The in-memory assembly technique — browser fetches a clean file plus instructions and builds malware locally — is worth discussing as a pattern that defeats conventional network detection, and whether your team's endpoint protection would catch it.