Cybersecurity researchers disclosed a persistent cross-site scripting (XSS) vulnerability in the web-based administration panel used to operate the StealC information-stealer, enabling defenders to compromise the criminals’ own management interface. CyberArk researcher Ari Novick reported that insufficient input sanitization in the panel allowed injected JavaScript to execute in authenticated operator sessions, which in turn enabled collection of system fingerprints, monitoring of active/live sessions, and exfiltration of session cookies from StealC operators.
Reporting indicates the access provided unusual visibility into StealC operator tradecraft and operational security failures, including the ability to infer operator environment details (e.g., IP/location and hardware characteristics when an operator accessed the panel without a VPN). StealC has been active since January 2023 as a malware-as-a-service (MaaS) stealer and has been distributed via multiple lures and channels (including YouTube-based distribution and other social-engineering delivery methods); recent iterations included panel redesigns and added features such as Telegram notifications, and a subsequent leak of the panel source code helped create conditions for researchers to identify and exploit weaknesses in the operator infrastructure while withholding full exploit specifics to avoid rapid patching or copycat abuse.

Pull IOCs and campaign context straight into your stack.
8 events from the most recent confirmed update back to the earliest known activity.
On January 19, 2026, multiple reports described CyberArk's disclosure of the StealC admin panel XSS issue and the operational insights it yielded into StealC users. As of the disclosure, there was no public confirmation that the vulnerability had been patched.
Using the panel flaw, researchers collected browser and system fingerprints, exfiltrated session cookies, and impersonated operators to observe backend activity such as reviewing stolen credentials and managing infected endpoints. Their investigation also profiled the active operator "YouTubeTA" and found no evidence that APT groups had exploited this specific XSS.
CyberArk researcher Ari Novick identified a persistent XSS vulnerability in the StealC web-based control panel caused by insufficient sanitization of user-supplied input. The flaw allowed code execution in authenticated operator sessions.
In mid-July 2025, the operator dubbed "YouTubeTA" reportedly failed to use a VPN, exposing a real IP address linked to Ukrainian ISP TRK Cable TV. The mistake supported an assessment that the actor was likely a Russian-speaking individual in Eastern Europe.
After the release of StealC V2, its panel source code was leaked, giving researchers the ability to analyze the malware operators' backend environment and identify weaknesses. This leak enabled later investigation of the panel's XSS flaw.
StealC version 2.0 introduced a redesigned administration panel and features including Telegram bot notifications. The vulnerable admin panel version confirmed by researchers was released in April 2025.
During 2025, a StealC operator tracked as "YouTubeTA" used hijacked YouTube accounts to promote fake cracked software, including pirated Adobe tools, to distribute the malware. The activity appeared aimed in part at stealing YouTube creator accounts to expand propagation.
StealC, a malware-as-a-service information stealer, was first seen in January 2023. It later spread through lures such as cracked software, rogue files, and fake CAPTCHA-style social engineering.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
rescana.com
Open sourcethehackernews.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.