Researchers Crack Open JSCeal, a Crypto-Stealing Malware Hidden in Compiled Code
Security researchers at Check Point have detailed a method for analysing JSCeal, a stealer malware targeting cryptocurrency applications that has been active since March 2024. Also known as WEEVILPROXY or MeadowLocust, JSCeal is delivered as compiled V8 bytecode rather than readable JavaScript, running through a bundled Node.js environment. This makes it far harder for analysts to inspect, as the code is first heavily obfuscated and then compiled into a format that standard reverse-engineering tools struggle to read.
This approach is attractive to attackers because it is cheap to build using existing Node.js tools and public obfuscation software, while making the malware expensive to analyse. To counter this, Check Point built on an open-source decompiler called View8, adding new techniques to reconstruct strings, unravel disguised control flow, and reveal the malware's underlying logic. The result is not a perfect recovery of the original code, but enough structure to trace how the malware behaves.
Using this method, researchers examined a real JSCeal sample and found capabilities including theft of browser and cryptocurrency data, keylogging, screenshot capture, and a local proxy used to intercept encrypted HTTPS traffic. These functions suggest the malware is designed to quietly harvest sensitive financial and credential information from infected systems.