JSCeal is a cryptocurrency-focused infostealer implemented as heavily obfuscated JavaScript compiled into V8 bytecode and executed through a bundled Node.js runtime. Also tracked as WEEVILPROXY and MeadowLocust, it has been active since at least 2024 and has targeted cryptocurrency users, retail traders, and holders of high-value online accounts. Campaign activity has overlapped with the WEEVILPROXY/MeadowLocust cluster; reporting has also identified overlap with the SourTrade malvertising operation, although this does not establish a definitive operator attribution.
JSCeal is distributed through malicious advertising and counterfeit cryptocurrency- and trading-related websites, commonly using bogus TradingView installers. The multi-stage delivery chain uses host fingerprinting, gating, PowerShell-based execution, and a bundled runtime to hinder automated analysis and selectively deploy the final payload. Later variants added payload encryption and macOS targeting.
The malware enumerates Chromium-based browsers and steals stored credentials, cookies, OAuth tokens, browsing data, and other browser secrets. It can reconstruct browser sessions by injecting stolen cookies and automate parts of Google authentication to obtain fresh OAuth tokens. JSCeal also targets Telegram session data, records keystrokes, captures screenshots, and collects cryptocurrency account and balance information.
JSCeal establishes a local HTTPS interception proxy by installing a locally generated certificate, allowing it to intercept and modify selected traffic. Its service-specific handlers can manipulate content and authentication workflows for cryptocurrency services, including Binance, Bybit, Ledger, and Kraken. Obfuscation layers, compiled V8 bytecode, control-flow flattening, encrypted strings, and wrapper functions substantially complicate static and dynamic analysis.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
JSCeal is a compiled V8 JavaScript malware distributed through malicious ads and fake cryptocurrency-trading pages posing as TradingView installers. It steals browser data, performs surveillance, and intercepts traffic through a local proxy.
JSCeal is a compiled V8 JavaScript malware distributed through malicious ads and fake cryptocurrency-trading pages posing as TradingView installers. It steals browser data, performs surveillance, and intercepts traffic through a local proxy.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
"The malware enumerates the Google accounts displayed in the current session" and, after injecting stolen cookies, handles Google authentication branches and tries recovered passwords. | “When a password challenge is reached, JSCeal iterates over the candidate passwords associated with that account.”
"The malware enumerates the Google accounts displayed in the current session" and, after injecting stolen cookies, handles Google authentication branches and tries recovered passwords. | “When a password challenge is reached, JSCeal iterates over the candidate passwords associated with that account.”
"The malware enumerates the Google accounts displayed in the current session" and, after injecting stolen cookies, handles Google authentication branches and tries recovered passwords. | “When a password challenge is reached, JSCeal iterates over the candidate passwords associated with that account.”
The JavaScript is heavily obfuscated, then compiled into V8’s internal bytecode representation and shipped as cached data rather than source code.
"The final JSC payload is distributed in Brotli-compressed form and decompressed by preflight.js."
It delivers assembly instructions to the victim's browser, retrieves a clean legitimate file from separate infrastructure, and directs the browser to build the final malware in memory on the victim’s machine. No finished malware ever exists on the network.
The authors introduced another obstacle by adding an AES-256-CBC encryption layer around the Brotli-compressed payload.
The campaign impersonated trusted trading and cryptocurrency brands, including Solana, Luno, and TradingView, to present copies of their portals.
"The malware enumerates the Google accounts displayed in the current session" and, after injecting stolen cookies, handles Google authentication branches and tries recovered passwords. | “When a password challenge is reached, JSCeal iterates over the candidate passwords associated with that account.”
JSCeal steals saved passwords and cookies from eight different Chromium-based browsers, harvests Telegram session data, logs keystrokes, takes screenshots.
When it hits a password prompt, it tries every credential it previously stole from that same machine until one works, then walks away with a fresh, valid OAuth token.
The malware can launch a victim’s own installed browser, inject stolen session cookies, and navigate through Google’s actual account authentication flow.
"It also queries all installed applications and targets Telegram accounts" with the recovered string "listTelegramSessions."
JSCeal steals saved passwords and cookies from eight different Chromium-based browsers, harvests Telegram session data, logs keystrokes, takes screenshots.
"The URL builder constructs an RPC endpoint in the form https://api.<domain>/rpc or wss://api.<domain>/rpc" and the HTTP transport posts "application/octet-stream" data.
120 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cryptocurrency-focused information stealer that is heavily obfuscated and compiled into V8 bytecode for execution through a bundled Node.js runtime. It steals saved browser credentials and cookies, Telegram session data, keystrokes, and screenshots. It can install an attacker-controlled local certificate to intercept and modify HTTPS traffic, including altering content for Binance, Bybit, and Ledger. It also automates Google authentication using stolen cookies and previously harvested credentials to obtain valid OAuth tokens. Later samples added AES-256-CBC encryption around Brotli-compressed payloads and expanded to macOS.
A sophisticated compiled V8 JavaScript information stealer and surveillance tool. It enumerates Chromium-based browsers; extracts passwords, cookies, OAuth tokens, and other stored secrets; can replay stolen browser sessions to bypass Google authentication; captures keystrokes and screenshots; and installs a local proxy that intercepts and modifies selected cryptocurrency-service traffic, including Binance, Bybit, and Ledger. Its payload uses javascript-obfuscator layers including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers.
Compiled V8 JavaScript malware that enumerates Chromium-based browsers and steals saved passwords, cookies, OAuth tokens, and other browser secrets. It can replay stolen browser sessions to access Google accounts, log keystrokes, capture screenshots, and install a local proxy to intercept and modify requests and responses for cryptocurrency services, including Binance, Bybit, and Ledger.
An information-stealing malware delivered as compiled V8 JavaScript bytecode (.jsc) and run through a bundled Node.js runtime. It targets cryptocurrency applications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.