Back to all news
Security

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

The Hacker News·September 7, 2026·1 min read
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

Cybersecurity researchers unpacked JSCeal, a sophisticated compiled V8 JavaScript malware with credential harvesting, surveillance, and traffic-interception capabilities. Check Point Research said the payloads are protected with javascript-obfuscator, using techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers, enabling it to bypass Google authentication using stolen session cookies.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store