Malware Bypasses Google Authentication via Stolen Browser Session Cookies
JSCeal is an advanced infostealer malware family that has rapidly evolved to become a significant threat to organizations and individuals, particularly those involved in cryptocurrency and digital asset management. Its most alarming capability is the circumvention of Google authentication mechanisms, including two-factor and multi-factor authentication (2FA/MFA), by leveraging stolen browser session cookies.
This allows attackers to hijack authenticated sessions and gain unauthorized access to Google accounts and associated services without requiring user credentials or OTPs.
JSCeal is distributed as highly obfuscated, compiled V8 bytecode, executed via a bundled Node.js runtime, and employs multiple layers of encryption and anti-analysis techniques.