30
42
30
47
30
42
42
30
60
60
42
42
42
30
42
55
42
60
60
30
42
47
30
30
30
30
30
60
42
42
Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode
Check Point's hasherezade details static deobfuscation of JSCeal, a V8-bytecode stealer targeting cryptocurrency applications since March 2024.
JSCeal is an infostealer distributed as compiled V8 bytecode (.jsc) executed by a bundled Node.js runtime, aimed at cryptocurrency applications. Other vendors track the same family under the names WEEVILPROXY or MeadowLocust. Check Point Research has tracked the campaign since early 2024, with activity dating back to March 2024. The write-up presents a static approach to unpacking the bytecode without executing it.
55
30
30
55
42
30
30
42
55
42