JSCeal malware activity
Malware Activity
Summary
Hide ▲
Show ▼
JSCeal is a compiled V8 JavaScript malware that now stands out for credential harvesting, session replay, and traffic interception against browser data. The malware can extract cookies, passwords, and OAuth tokens, then use stolen session data to bypass authentication and access victim accounts. It also adds keystroke logging, screenshots, and proxy-based request modification, increasing both theft and surveillance risk.
Related Happenings
KREMLIN browser-extension credential theft activity
Malware Activity
H score44
First: 15.09.2026 21:54
Last: 15.09.2026 21:54
Sources 1
About this happening:
The KREMLIN malware activity is a Brazilian banking operation that has been active since at least May 2025 and uses malicious Chrome and Edge extensions to steal *...
KREMLIN browser-extension credential theft activity
Malware ActivityAbout this happening: The KREMLIN malware activity is a Brazilian banking operation that has been active since at least May 2025 and uses malicious Chrome and Edge extensions to steal *...
Latest development: 16.09.2026 21:50
Elastic Security Labs registered a domain used as an anti-sandbox canary to break the KREMLIN loader, and confirmed 1,515 infected systems, almost all in Brazil.
ClickFix malicious JavaScript browser crypto-skimmer activity
Malware Activity
H score16
First: 09.09.2026 16:45
Last: 09.09.2026 16:45
Sources 1
About this happening:
A ClickFix payload now uses malicious JavaScript inside browser sessions to steal cryptocurrency deposits and copied addresses. The code is delivered through the Google...
ClickFix malicious JavaScript browser crypto-skimmer activity
Malware ActivityAbout this happening: A ClickFix payload now uses malicious JavaScript inside browser sessions to steal cryptocurrency deposits and copied addresses. The code is delivered through the Google...
SourTrade malvertising campaign impersonating trading and cryptocurrency brands
Campaign
H score34
First: 07.09.2026 10:53
Last: 07.09.2026 10:53
Sources 1
How related:
The campaign is assessed to be active since late 2024, targeting retail traders and cryptocurrency investors across 12 countries in 25 languages, primarily in Asia Pacific and Latin America.
About this happening:
The SourTrade malvertising campaign remains active, using lookalike portals and malicious JavaScript to target retail traders and cryptocurrency investors across *...
SourTrade malvertising campaign impersonating trading and cryptocurrency brands
CampaignHow related: The campaign is assessed to be active since late 2024, targeting retail traders and cryptocurrency investors across 12 countries in 25 languages, primarily in Asia Pacific and Latin America.
About this happening: The SourTrade malvertising campaign remains active, using lookalike portals and malicious JavaScript to target retail traders and cryptocurrency investors across *...
ClickFix AmnesiaStealer distribution campaign targeting mac users
Campaign
H score22
First: 14.08.2026 13:45
Last: 14.08.2026 13:45
Sources 1
About this happening:
A ClickFix campaign is distributing AmnesiaStealer to macOS users through a counterfeit GitHub "Download for macOS" page and a copy-and-paste command that launches...
ClickFix AmnesiaStealer distribution campaign targeting mac users
CampaignAbout this happening: A ClickFix campaign is distributing AmnesiaStealer to macOS users through a counterfeit GitHub "Download for macOS" page and a copy-and-paste command that launches...
Latest development: 16.08.2026 18:07
Jamf described AmnesiaStealer's stream_module and remote_stream commands, which copy a victim's Chromium profile into a hidden headless browser and open WebSocket and Chrome DevTools Protocol channels through webSocketDebuggerUrl. The operator can issue navigation and mouse commands, receive live screencasts, and export or import cookies to operate online portals inside the victim's authenticated sessions on Google Chrome, Microsoft Edge, Vivaldi, Arc, Opera, Brave, and Chromium.
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware Activity
H score16
First: 14.08.2026 13:45
Last: 14.08.2026 13:45
Sources 1
About this happening:
AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware ActivityAbout this happening: AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...
Timeline
-
07.09.2026 10:53 2 articles · 13d ago
JSCeal malware activity
Initial DisclosureJSCeal was first documented in July 2025 as a compiled V8 JavaScript malware family. The initial reporting tied it to fake cryptocurrency trading sites and browser-focused credential theft.
Show sources
- JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies — thehackernews.com — 07.09.2026 10:53
- JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies — thehackernews.com — 07.09.2026 10:53