ZeroHour
Check Point Researchpublished ()ingested [email protected]

Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode

mediumMalware exploited in the wildimportance 55
AI summary · glm-5.3-flash

Check Point's hasherezade details static deobfuscation of JSCeal, a V8-bytecode stealer targeting cryptocurrency applications since March 2024.

JSCeal is an infostealer distributed as compiled V8 bytecode (.jsc) executed by a bundled Node.js runtime, aimed at cryptocurrency applications. Other vendors track the same family under the names WEEVILPROXY or MeadowLocust. Check Point Research has tracked the campaign since early 2024, with activity dating back to March 2024. The write-up presents a static approach to unpacking the bytecode without executing it.

  • JSCeal is delivered as compiled V8 bytecode (.jsc) run by a bundled Node.js runtime
  • Stealer targets cryptocurrency applications and has been active since March 2024
  • Check Point publishes a static deobfuscation technique for V8 bytecode
  • Same family is also tracked as WEEVILPROXY and MeadowLocust
Full article

Research by: hasherezade Key Points Introduction JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (other vendors also tag it with the names WEEVILPROXY or MeadowLocust). Its campaign activity dates back to March 2024 [1]; Check Point Research has been tracking the malware since early […] The post Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode appeared first on Check Point Research.

This source does not provide full text. Read it at research.checkpoint.com.