The JSCeal infostealer malware is actively bypassing Google 2FA and MFA by hijacking authenticated browser session cookies, allowing attackers to gain full account access without OTPs.
First observed in March 2024, the malware targets Chromium-based browsers like Chrome and Edge to exfiltrate passwords, OAuth tokens, and cryptocurrency wallet data.
JSCeal uses obfuscated V8 bytecode and a Node.js runtime to evade detection, with recent campaigns in June 2026 targeting high-value cryptocurrency exchanges like Binance and Bybit.