Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode
ID: 7a85c251-46c3-50f3-bfc2-8ea575bc69d3
STIX ID: report--7a85c251-46c3-50f3-bfc2-8ea575bc69d3
Feed Name: Check Point Research
Check Point Research describes JSCeal, a actively developed, Node.js-bundled stealer delivered as V8 bytecode that targets cryptocurrency users and performs credential/cookie theft, keylogging, screenshots, local HTTPS interception with attacker-controlled certificates, and automated session replay using Puppeteer; the paper also presents a deterministic, static deobfuscation pipeline (based on View8) and optional LLM-assisted renaming to recover readable pseudocode and extract artifacts, IOCs, and platform-specific capabilities across 23+ analyzed payloads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
