Technology

JSCeal Malware Bypasses 2FA Using Stolen Browser Session Cookies

Rescana2h
THE BRIEF
1

The JSCeal infostealer malware is actively bypassing Google 2FA and MFA by hijacking authenticated browser session cookies, allowing attackers to gain full account access without OTPs.

2

First observed in March 2024, the malware targets Chromium-based browsers like Chrome and Edge to exfiltrate passwords, OAuth tokens, and cryptocurrency wallet data.

3

JSCeal uses obfuscated V8 bytecode and a Node.js runtime to evade detection, with recent campaigns in June 2026 targeting high-value cryptocurrency exchanges like Binance and Bybit.