JSCEAL is a Windows-focused information-stealing malware family that targets cryptocurrency users and other victims with valuable online accounts. It is also tracked under the alias WeevilProxy. The malware is notable for being implemented as compiled V8 JavaScript bytecode executed through a bundled Node.js runtime, with heavy obfuscation and anti-analysis measures intended to hinder reverse engineering and signature-based detection.
JSCEAL has been distributed through fake cryptocurrency and trading application installers, including TradingView-themed lures, and through malicious social-media advertising and related malvertising infrastructure. Campaigns associated with the malware have used counterfeit landing pages, staged installers, and victim fingerprinting to qualify targets before delivering the final payload. Reporting links the activity to long-running campaigns aimed at retail traders and cryptocurrency holders.
Once deployed, JSCEAL can steal browser credentials, cookies, autofill data, cryptocurrency wallet information, and Telegram session data. Documented capabilities also include keylogging, screenshot capture, collection of host information, local HTTPS interception through installation of an attacker-controlled certificate and proxying, and script injection into banking and cryptocurrency websites to steal data in real time. The malware has also been described as capable of manipulating cryptocurrency wallets and supporting adversary-in-the-middle activity. Some reporting characterizes it as providing remote-access functionality in addition to its theft features.
Operationally, JSCEAL has evolved over time with redesigned command-and-control infrastructure, gated multi-stage delivery, and updated execution logic to improve stealth. Observed changes include stronger anti-analysis controls, selective payload access, and persistence mechanisms leveraging Windows scheduling components via COM rather than simpler task-creation patterns. The malware represents a significant threat to Windows users involved in cryptocurrency trading, wallet management, and other high-value financial activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The browser retrieves and decompresses a clean Bun runtime... Base64 blobs in the configuration supply the Portable Executable (PE) header, section table, and a .bun section containing malicious JavaScriptCore bytecode for app.js.
Run across twenty real JSCeal payloads, the pipeline surfaced browser and cryptocurrency theft, Telegram session collection, keylogging, screenshot capture, and a local HTTPS interception proxy that installs an attacker controlled certificate, all recovered statically.
Run across twenty real JSCeal payloads, the pipeline surfaced browser and cryptocurrency theft, Telegram session collection, keylogging, screenshot capture, and a local HTTPS interception proxy that installs an attacker controlled certificate, all recovered statically.
Он мог похищать пароли, файлы cookie и данные криптокошельков, перехватывать трафик и нажатия клавиш, а также делать скриншоты.
Run across twenty real JSCeal payloads, the pipeline surfaced browser and cryptocurrency theft, Telegram session collection, keylogging, screenshot capture, and a local HTTPS interception proxy that installs an attacker controlled certificate, all recovered statically.
The DLL modules are designed to parse the POST requests from the website and gather system information and commence the fingerprinting process... Other functions of JSCEAL include gathering system information...
Run across twenty real JSCeal payloads, the pipeline surfaced browser and cryptocurrency theft, Telegram session collection, keylogging, screenshot capture, and a local HTTPS interception proxy that installs an attacker controlled certificate, all recovered statically.
Run across twenty real JSCeal payloads, the pipeline surfaced browser and cryptocurrency theft, Telegram session collection, keylogging, screenshot capture, and a local HTTPS interception proxy that installs an attacker controlled certificate, all recovered statically.
Run across twenty real JSCeal payloads, the pipeline surfaced browser and cryptocurrency theft, Telegram session collection, keylogging, screenshot capture, and a local HTTPS interception proxy that installs an attacker controlled certificate, all recovered statically.
The malware, besides establishing connections with a remote server to receive further instructions...
The malware... sets up a local proxy with the goal of intercepting the victim's web traffic and injecting malicious scripts into banking, cryptocurrency, and other sensitive websites.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cryptocurrency-focused stealer delivered as compiled V8 JavaScript bytecode, wrapped in Brotli compression and executed via a bundled Node.js runtime. The analyzed payloads supported browser and cryptocurrency theft, Telegram session collection, keylogging, screenshot capture, and a local HTTPS interception proxy that installs an attacker-controlled certificate.
Stealer previously distributed in a related fake-TradingView malvertising campaign; capable of stealing passwords, cookies, and crypto-wallet data, intercepting traffic and keystrokes, and taking screenshots.
A stealer payload identified in an earlier related TradingView malvertising cluster. The article says earlier reporting documented credential theft, keylogging, traffic interception, wallet theft, and remote-access capabilities, but notes these capabilities cannot yet be assigned to the current files discussed by Confiant.
Compiled V8 JavaScript malware delivered via fake crypto trading apps promoted through Facebook ads; steals credentials/wallet data (per summary).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.