Story perspectives
Check Point: JSCeal Steals Browser Logins, Bypasses Google 2FA
9/8/2026
1 of 1
Story summary
- Check Point Research disclosed that JSCeal steals browser credentials and bypasses Google 2FA.
- JSCeal extracts passwords, cookies and OAuth tokens from eight Chromium browsers.
- JSCeal installs a local HTTPS proxy with attacker-generated certificates, altering traffic on Binance, Bybit and Ledger.
- Newer samples first seen on 2025-11-11 add AES-256-CBC encryption, macOS support and use PowerShell ZIP archives.
