Breaking the Seal: Static Deobfuscation of JSCeal's Compiled V8 Bytecode
released on 2026-08-31 @ 02:00:19 PM
Check Point Research developed a fully static deobfuscation pipeline to analyze JSCeal, a sophisticated cryptocurrency-focused stealer delivered as compiled V8 bytecode. The malware uses javascript-obfuscator with multiple protection layers including RC4-encrypted strings, control-flow flattening, and proxy functions. The toolkit transforms View8 pseudocode without executing samples, enabling detailed analysis of capabilities including keylogging, browser credential theft, cryptocurrency collection, HTTPS traffic interception through a local MITM proxy, and active session replay using stolen cookies. Recent JSCeal variants have evolved to target macOS, use newer V8 versions, and add AES-256-CBC encryption layers around payloads, demonstrating active development.