Skip to content
Back to Guavy Wire
Stocks

Sophisticated Malware Bypasses Google Authentication with Stolen Cookies

Instruments
GOOGL MSFT
Share

Cybersecurity researchers have uncovered JSCeal, a sophisticated compiled V8 JavaScript malware that can bypass Google authentication using stolen session cookies. The threat actors use fake cryptocurrency trading sites to trick unsuspecting users into downloading malicious software.

JSCeal is protected with javascript-obfuscator, which makes analysis and reverse-engineering harder. Check Point Research developed a deobfuscation pipeline to decode the malware's bytecode, revealing its execution flow and features.

The browser-stealing module targets Chromium-based browsers, including Google Chrome, Microsoft Edge, and Brave, extracting cookies and passwords from user profiles. JSCeal can also leverage stolen cookie data to conduct active session replay attacks and gain unauthorized access to a victim's Google account.

More on Stocks

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc