V8 malware bypasses Google authentication and MFA protections
Malware using compiled V8 JavaScript is stealing Google session tokens to bypass MFA entirely. The JSCeal campaign bundles the V8 engine with Node.js, obfuscates code using RC4 encryption, and harvests authentication cookies instead of credentials. Session tokens remain valid even after password resets, so MFA provides no protection once the endpoint is compromised. The campaign has been active since late 2024 across 12 countries.
Meanwhile, Intel's Dynamic PAMT patches land in Linux 7.4, cutting TDX memory overhead by allocating metadata on-demand instead of at boot.
In this issue:
- JSCeal malware: V8-compiled payloads steal Google session tokens
- Intel Dynamic PAMT: on-demand TDX metadata for Linux 7.4
- AMD Zen 6: BTB context isolation eliminates SafeRET overhead
- Mystery x86 chip: APX, FRED, and x86S deployed at production scale
JSCeal Malware Bypasses Google MFA Using Compiled V8 and Session Tokens
The Signal
Malvertising campaign delivers Node.js-embedded V8 payloads that steal Google session cookies, bypassing MFA entirely.
What Changed
- Malware compiles JavaScript using V8 engine bundled with Node.js runtime for execution.
- Uses javascript-obfuscator with RC4 string encryption and control-flow flattening for evasion.
- Harvests Google authentication session tokens from browser storage, not credentials directly.
- Campaign active since late 2024 across 12 countries via fake TradingView ads.
- Deploys surveillance modules with traffic interception and credential logging capabilities.
Operational Impact
Session token theft bypasses MFA because tokens represent already-authenticated sessions. Google cookies remain valid even after password resets. Traditional endpoint detection may miss compiled JavaScript payloads since they execute as native V8 bytecode. Organizations relying on MFA for Google Workspace accounts face exposure if endpoint browsers are compromised. Session token lifetimes determine attack windows.
Watch For
Monitor for unexpected Node.js processes and browser cookie access patterns. Session token binding and device attestation would limit this technique but require browser and identity provider support.
Intel Dynamic PAMT Queued for Linux 7.4 to Reduce TDX Memory Overhead
The Signal
Intel's Dynamic PAMT merges to Linux 7.4, cutting TDX memory overhead via on-demand metadata allocation.
What Changed
- TDX reserves ~0.4% of system RAM for PAMT (Physical Address Metadata Table) tracking.
- Dynamic PAMT allocates PAMT memory on-demand instead of at boot.
- On a 2TB server, this saves roughly 8GB of upfront reservation.
- Feature lands in tip/tip.git x86/tdx branch after year-long development cycle.
- Enabled by default on CPUs with Dynamic PAMT support.
Operational Impact
TDX uses PAMT to track page state for confidential VMs. Current implementation pre-allocates metadata for all system memory at boot. Dynamic PAMT defers allocation until pages are actually assigned to TDX guests. Teams running high-density confidential VM workloads on multi-terabyte hosts will reclaim gigabytes of idle overhead. No configuration changes required—kernel detects capability and enables automatically.
Watch For
Linux 7.4 merge window opens late September. Check `/proc/cpuinfo` for Dynamic PAMT flag on 5th Gen Xeon and later.
AMD Zen 6 Adds BTB Context Isolation Against Speculative Attacks
The Signal
AMD Zen 6 CPUs add BTB context isolation between user/kernel and guest/host, kernel patches reveal.
What Changed
- BTB isolation separates branch prediction state across privilege and virtualization boundaries.
- SafeRET mitigation for SRSO vulnerability no longer needed on Zen 6 processors.
- Spectre v2 IBPB still required on context switch for user/user and guest/guest isolation.
- Patch queued for tip/tip.git x86/bugs branch, targeting Linux 7.4 release.
- First public disclosure of Zen 6 silicon security architecture changes.
Operational Impact
Zen 6 systems will drop SafeRET overhead that affected Zen 1-4 generations after SRSO disclosure. IBPB-based Spectre v2 mitigations remain mandatory for same-privilege context switches. Performance gains depend on workload context switch frequency and current SafeRET configuration.
Watch For
Linux 7.4 merge window and Zen 6 silicon availability. Attack surface for user-to-user BTB poisoning unchanged from prior generations.
Mystery x86 Implementation Ships with APX, FRED, and x86S—Advancing Where Intel Left Off
The Signal
Unknown vendor deployed production x86 CPU with APX, FRED, and x86S legacy-free architecture at scale.
What Changed
- System runs PM64-only mode, dropping all 16-bit and 32-bit compatibility.
- APX (Advanced Performance Extensions) doubles general-purpose registers from 16 to 32.
- FRED (Flexible Return and Event Delivery) replaces IDT-based interrupt handling.
- AMX implementation supports 16-tile and 32-tile configurations, exceeding current Intel Xeon specs.
- Deployment confirmed operational for over one year via x86 expert Christian Ludloff.
Operational Impact
This is the first x86S deployment despite Intel abandoning the specification in 2024. The PM64-only requirement means no legacy BIOS, no 32-bit userspace, and no compatibility mode—breaking decades of backward compatibility assumptions. Software built for traditional x86-64 will need recompilation to exploit APX's extended register set. FRED's event delivery changes require OS kernel modifications for interrupt and exception handling.
Watch For
ISA fragmentation risk increases if this vendor's extensions diverge from Intel/AMD roadmaps. Monitor whether Intel or AMD responds by resuming x86S development or extending compatibility guarantees.
Quick Reads
- JSCeal Malware — V8-based malware steals Google session tokens, completely bypassing MFA protections.
- Intel Dynamic PAMT — Linux 7.4 reduces TDX memory overhead by allocating metadata on-demand.
- AMD Zen 6 — New CPUs add BTB context isolation, eliminating SafeRET mitigation overhead.
- Mystery x86 CPU — Unknown vendor deploys APX, FRED, and legacy-free x86S architecture at scale.
Subscribe to Signal Field
Data & infrastructure news. Subscribers get new posts by email a day before they go live on the site.
Email signup is coming soon — in the meantime, follow the Signal Field RSS feed.