ThreatCluster

JSCeal Crypto Stealer Exploits Compiled V8 Bytecode for Credential Theft

First seen 1 Sep 2026, 21:30 UTC Research.CheckpointGbhackers 58

Article Content

Browse articles
ThreatCluster

JSCeal is a sophisticated information stealer targeting cryptocurrency applications, delivered as compiled V8 bytecode (.jsc) executed by a bundled Node.js runtime. It has been active since March 2024 and is also known as WEEVILPROXY or MeadowLocust. The malware's obfuscation technique complicates detection and analysis, making it a significant threat to users of cryptocurrency platforms. Check Point Research has been monitoring this malware closely, providing insights into its operation and deobfuscation methods. The attack primarily affects users who interact with cryptocurrency wallets and exchanges, potentially leading to unauthorized access to sensitive information. Current mitigation strategies are limited due to the complexity of the malware's delivery method.

Key Points: • JSCeal targets cryptocurrency applications using obfuscated V8 bytecode. • The malware has been active since March 2024, complicating detection efforts. • It is also known as WEEVILPROXY and MeadowLocust, highlighting its widespread recognition.

Timeline

2024-03-01
JSCeal campaign activity begins
JSCeal starts targeting cryptocurrency applications, utilizing advanced obfuscation techniques.
Research.Checkpoint
2026-08-31
Research on JSCeal published
Check Point Research releases findings on JSCeal's deobfuscation and operational methods.
Research.Checkpoint
2026-09-01
Gbhackers article published
Gbhackers reports on JSCeal's sophisticated delivery method and its implications for cybersecurity.
Gbhackers