JSCeal Malware Bypasses Google Authentication via Stolen Session Cookies
Check Point Research identifies sophisticated JavaScript malware targeting credential harvesting and session hijacking

Key Takeaways
- JSCeal is a compiled V8 JavaScript malware with credential harvesting and surveillance capabilities
- The malware can bypass Google authentication by reusing stolen session cookies
- Obfuscation techniques including RC4-protected strings and control-flow flattening hinder analysis
- Session cookie theft enables bypass of multi-factor authentication protections
Related Security News

Star Blizzard Campaign Targets 100+ Organizations with Fake Event Invitations
Microsoft reports that the Russian state-sponsored threat actor Star Blizzard has been conducting a sustained campaign since January 2026, using fake event invitations to trick targets into installing a backdoor on Windows computers. The operation has affected more than 100 organizations, primarily in the U.S. and U.K., with victims tied to Ukraine. At least one infection has been confirmed, though the full extent of breaches and data exfiltration remains unverified.




