JSCEAL, also tracked as WeevilProxy, is a Windows-focused information-stealing malware family used in campaigns targeting cryptocurrency users, retail traders, and holders of high-value online accounts. It has been distributed through fake trading and cryptocurrency application installers, including counterfeit copies of well-known market and wallet-related software, and has been heavily promoted through malicious social media advertising and related malvertising infrastructure.
The malware is implemented as compiled JavaScript and has been described as using a compiled V8 or JavaScriptCore-based runtime in different observed delivery chains. Operators have used multi-stage infection workflows with strong gating and anti-analysis controls, including victim fingerprinting, cloaked landing pages, staged payload retrieval, and infrastructure changes intended to frustrate automated analysis and signature-based detection. In some campaigns, the delivery chain required coordination between a malicious website and a locally running installer component, with localhost communications used to exchange status and victim data before the final payload was executed. Later activity also showed redesigned command-and-control patterns, gated access requiring specific PowerShell behavior, and stealthier persistence-related task scheduling methods.
JSCEAL’s core function is credential and financial data theft. Reported capabilities include theft of usernames, passwords, browser cookies, and saved browser data; collection of cryptocurrency wallet information; and theft of Telegram-related data. It has also been observed logging keystrokes, capturing screenshots, gathering host information, and exfiltrating collected data to attacker-controlled infrastructure. Beyond classic infostealing, JSCEAL has been associated with local proxying and traffic interception that enable adversary-in-the-middle style abuse, including script injection into banking and cryptocurrency-related web sessions to steal data in real time and manipulate wallet activity.
The malware has been linked by multiple vendors to TradingView-themed malvertising clusters active from 2024 onward, with subsequent evolution in 2025 and 2026 showing improved stealth, updated infrastructure, and continued focus on cryptocurrency-centric victims. High-confidence reporting consistently characterizes JSCEAL as an active and evolving threat in financially motivated campaigns rather than a commodity nuisance family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The browser retrieves and decompresses a clean Bun runtime... Base64 blobs in the configuration supply the Portable Executable (PE) header, section table, and a .bun section containing malicious JavaScriptCore bytecode for app.js.
Он мог похищать пароли, файлы cookie и данные криптокошельков, перехватывать трафик и нажатия клавиш, а также делать скриншоты.
Он мог похищать пароли, файлы cookie и данные криптокошельков, перехватывать трафик и нажатия клавиш, а также делать скриншоты.
The DLL modules are designed to parse the POST requests from the website and gather system information and commence the fingerprinting process... Other functions of JSCEAL include gathering system information...
Он мог похищать пароли, файлы cookie и данные криптокошельков, перехватывать трафик и нажатия клавиш, а также делать скриншоты.
The malware, besides establishing connections with a remote server to receive further instructions...
The malware... sets up a local proxy with the goal of intercepting the victim's web traffic and injecting malicious scripts into banking, cryptocurrency, and other sensitive websites.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Stealer previously distributed in a related fake-TradingView malvertising campaign; capable of stealing passwords, cookies, and crypto-wallet data, intercepting traffic and keystrokes, and taking screenshots.
A stealer payload identified in an earlier related TradingView malvertising cluster. The article says earlier reporting documented credential theft, keylogging, traffic interception, wallet theft, and remote-access capabilities, but notes these capabilities cannot yet be assigned to the current files discussed by Confiant.
Compiled V8 JavaScript malware delivered via fake crypto trading apps promoted through Facebook ads; steals credentials/wallet data (per summary).
JavaScript-based stealer malware distributed via Facebook ads, with advanced anti-analysis and C2 infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.