Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: oauth-tokens (1 article)Clear

JSCeal malware steals session cookies to log into Google without the password

Researchers at Check Point analyzed JSCeal, malware compiled into a hard-to-analyze bytecode format that steals browser cookies and authentication tokens to hijack accounts. By replaying stolen session cookies, an attacker can access a victim's Google account without the password or a second factor, and the malware also grabs saved passwords, autofill data, and OAuth tokens to automate further account access. It additionally targets cryptocurrency wallets and platforms and includes keylogging, screenshots, and messaging-session theft. The compiled format and layered obfuscation push it outside analysts' usual tooling, though Check Point released a deobfuscator. It is a reminder that stolen session cookies quietly defeat passwords and multi-factor authentication alike.

Check
Treat session cookies as sensitive credentials: monitor endpoints for access to browser cookie databases and suspicious script-to-runtime execution chains, and shorten session lifetimes so stolen cookies expire sooner.
Affected
Users whose browsers are infected by this stealer; theft of session cookies and OAuth tokens lets attackers replay authenticated Google sessions without the password or second factor, and reach crypto accounts.
Fix
Bind sessions to devices where supported, expire and revoke sessions on anomalies, deploy endpoint detection for cookie theft and in-memory browser attacks, and monitor for session replay from unfamiliar locations.