logo

Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode

ID: 7a85c251-46c3-50f3-bfc2-8ea575bc69d3

STIX ID: report--7a85c251-46c3-50f3-bfc2-8ea575bc69d3

Feed Name: Check Point Research

Threat Score
78/100

Date Published: 2026-08-31

Date Updated: 2026-09-01

Author: [email protected]

...
...

Check Point Research describes JSCeal, a actively developed, Node.js-bundled stealer delivered as V8 bytecode that targets cryptocurrency users and performs credential/cookie theft, keylogging, screenshots, local HTTPS interception with attacker-controlled certificates, and automated session replay using Puppeteer; the paper also presents a deterministic, static deobfuscation pipeline (based on View8) and optional LLM-assisted renaming to recover readable pseudocode and extract artifacts, IOCs, and platform-specific capabilities across 23+ analyzed payloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.