CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5410

As cited

Copy frozen at (site build).

threat intel

Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode

Check Point Research documented a static deobfuscation pipeline for JSCeal, a cryptocurrency-focused stealer delivered as compiled V8 bytecode protected by multiple JavaScript obfuscation layers. The toolkit, released publicly, recovers pseudocode by removing string encryption, control-flow flattening, and proxy indirection without executing the malware. Recent JSCeal variants show evolution including runtime upgrades, additional encryption, and macOS targeting.

Why it matters: Security practitioners analyzing V8 bytecode-based malware now have a repeatable methodology and open-source toolkit to recover actionable intelligence; organizations running cryptocurrency platforms, browsers, and cloud services should assess exposure to JSCeal's credential theft, session replay, and HTTPS interception capabilities as active campaigns continue.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode

Check Point Research documented a static deobfuscation pipeline for JSCeal, a cryptocurrency-focused stealer delivered as compiled V8 bytecode protected by multiple JavaScript obfuscation layers. The toolkit, released publicly, recovers pseudocode by removing string encryption, control-flow flattening, and proxy indirection without executing the malware. Recent JSCeal variants show evolution including runtime upgrades, additional encryption, and macOS targeting.

Why it matters: Security practitioners analyzing V8 bytecode-based malware now have a repeatable methodology and open-source toolkit to recover actionable intelligence; organizations running cryptocurrency platforms, browsers, and cloud services should assess exposure to JSCeal's credential theft, session replay, and HTTPS interception capabilities as active campaigns continue.

VendorsMicrosoftAppleGoogleGitHubCheck PointZoom
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary