AI Weekly Malaysia

Back to items Summaries

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

ID
22070
Status
summarized
Published
07 Sep 2026, 3:53 PM
Fetched
07 Sep 2026, 6:38 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/jsceal-malware-can-bypass-google.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
4.5
Created
07 Sep 2026, 6:39 PM
Tags
Audience
developerssaas_founders

What happened

Check Point Research detailed JSCeal, a compiled V8 JavaScript malware that steals session cookies to bypass Google authentication, distributed via fake crypto trading sites impersonating brands like TradingView, Solana, and Luno. A related Confiant-documented campaign called SourTrade, active since late 2024, delivers assembly instructions to the victim's browser so the malware is built in-memory rather than transmitted as a finished file, targeting retail traders across 12 countries in APAC and Latin America.

Why it matters

If you build fintech, crypto, or trading products targeting APAC retail users, your users are actively being phished via lookalike ads impersonating brands like Luno and TradingView — consider user education and brand-monitoring for malvertising impersonation. The in-browser malware assembly technique means traditional network-based AV won't catch the payload, which matters if you rely on endpoint or network filtering for your team's devices.

Discussion angle

The in-memory assembly technique — browser fetches a clean file plus instructions and builds malware locally — is worth discussing as a pattern that defeats conventional network detection, and whether your team's endpoint protection would catch it.

Top