BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

XSS in StealC Panel Lets Researchers Steal Cookies, ID Actor

XSS in StealC control panel allowed session fingerprinting and cookie theft; leaked source code and weak cookie protections exposed operator details and a YouTube distributor that amassed ~5,000 logs, ~390,000 passwords and 30M+ cookies.

  • StealC panel contained an XSS flaw that let researchers capture system fingerprints, active sessions, and session cookies.
  • Leaked panel source code and poor cookie protections exposed operator and customer data, including one actor’s IP and hardware details.
  • A single customer, YouTubeTA, used YouTube to distribute the stealer and amassed thousands of logs, hundreds of thousands of passwords, and millions of cookies.

On Jan. 19, 2026, CyberArk researcher Ari Novick disclosed a cross-site scripting (XSS) flaw in the web control panel used by operators of the StealC information stealer, enabling collection of system fingerprints, session monitoring, and cookie theft, according to a report.

- Advertisement -

StealC first appeared in January 2023 as a Malware-as-a-service product that used YouTube to spread disguised cracked software. The malware later added features such as Telegram bot integration, improved payload delivery, and a redesigned administration panel known as StealC V2.

Weeks after the panel update, its source code was leaked, allowing researchers to analyze operator systems and retrieve active cookies, as detailed in an autopsy and a sample listing. XSS is a client-side injection that runs malicious JavaScript in a victim’s browser when sites fail to validate input, per MDN and a Fortinet explanation.

"By exploiting it, we were able to collect system fingerprints, monitor active sessions, and – in a twist that will surprise no one – steal cookies from the very infrastructure designed to steal them," Novick wrote in the report. The panel lacked basic protections such as httpOnly flags on cookies, leaving session cookies exposed.

Analysis identified a prominent customer named YouTubeTA, which promoted cracked Adobe products on YouTube and gathered over 5,000 logs containing about 390,000 stolen passwords and more than 30 million stolen cookies. Many of those cookies were tracking or non-sensitive cookies rather than high-value credentials.

- Advertisement -

Researchers also found a single admin account using an Apple M3 machine with English and Russian settings. An operational mistake in mid-July 2025 — failing to use a VPN — revealed a real IP tied to TRK Cable TV, suggesting the operator is a lone actor in an Eastern European, Russian-speaking area.

CyberArk noted that weaknesses in the panel and cookie handling exposed customer data and that similar flaws in other malware services could let researchers and law enforcement gather actionable intelligence, as stated in their report.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Sonic V2.2 doubles smart contract size limits for developers

Sonic V2.2 doubles the maximum deployed contract size from 24 KiB to 48 KiB...

ByteDance Secures $29.6B Loan from 30 Banks for AI Push

TikTok parent ByteDance secured a $29.6 billion loan from nearly 30 Chinese and international...

Musk: Tesla IPO value was a thousandth of current value

Tesla stock fell roughly 6% on Friday after the Cybercab launch event in Austin...

Tesla Cybercab stock crashes 6% on NHTSA audit

Tesla stock dropped 6% in an hour after the NHTSA opened a compliance audit...

Pineapple moves $1B mortgage records onto Injective blockchain

Pineapple Financial has migrated over $1 billion in residential mortgage records onto Injective, with...

Must Read

6 Best VPN Providers That Accept Monero

Privacy and anonymity are probably the most important things that we should all consider in today's internet era. Although there are a lot of...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading