Threat actors used Facebook advertisements impersonating a cryptocurrency exchange and promising digital-asset rewards to distribute the Node.js-based JSCEAL malware. Victims were routed to convincing counterfeit exchange sites that profiled browser, campaign, and operating-system information before serving platform-specific installers. AhnLab reported roughly 1,500 Windows and macOS infections in South Korea during August and September 2026.
On Windows, the campaign used a malicious BAT loader to invoke PowerShell, create scheduled-task persistence, add a Microsoft Defender exclusion, and execute JavaScript or V8 bytecode through an embedded Node.js runtime. On macOS, a fraudulent PKG installer downloaded shell scripts, collected and validated the user's password, exfiltrated host and clipboard data, registered a LaunchAgent for persistence, and launched additional JavaScript-based payloads. Organizations should treat cryptocurrency-reward advertising as a likely social-engineering lure and block or investigate related counterfeit exchange downloads.

Get the infrastructure and lures behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Threat actors used Facebook advertisements impersonating a cryptocurrency exchange and promising cryptocurrency rewards to distribute Node.js-based JSCEAL malware. Approximately 1,500 Windows and macOS systems in Korea were confirmed infected during August and September 2026.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourceasec.ahnlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.