BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

XSS in StealC Panel Lets Researchers Steal Cookies, ID Actor

XSS in StealC control panel allowed session fingerprinting and cookie theft; leaked source code and weak cookie protections exposed operator details and a YouTube distributor that amassed ~5,000 logs, ~390,000 passwords and 30M+ cookies.

  • StealC panel contained an XSS flaw that let researchers capture system fingerprints, active sessions, and session cookies.
  • Leaked panel source code and poor cookie protections exposed operator and customer data, including one actor’s IP and hardware details.
  • A single customer, YouTubeTA, used YouTube to distribute the stealer and amassed thousands of logs, hundreds of thousands of passwords, and millions of cookies.

On Jan. 19, 2026, CyberArk researcher Ari Novick disclosed a cross-site scripting (XSS) flaw in the web control panel used by operators of the StealC information stealer, enabling collection of system fingerprints, session monitoring, and cookie theft, according to a report.

- Advertisement -

StealC first appeared in January 2023 as a Malware-as-a-service product that used YouTube to spread disguised cracked software. The malware later added features such as Telegram bot integration, improved payload delivery, and a redesigned administration panel known as StealC V2.

Weeks after the panel update, its source code was leaked, allowing researchers to analyze operator systems and retrieve active cookies, as detailed in an autopsy and a sample listing. XSS is a client-side injection that runs malicious JavaScript in a victim’s browser when sites fail to validate input, per MDN and a Fortinet explanation.

"By exploiting it, we were able to collect system fingerprints, monitor active sessions, and – in a twist that will surprise no one – steal cookies from the very infrastructure designed to steal them," Novick wrote in the report. The panel lacked basic protections such as httpOnly flags on cookies, leaving session cookies exposed.

Analysis identified a prominent customer named YouTubeTA, which promoted cracked Adobe products on YouTube and gathered over 5,000 logs containing about 390,000 stolen passwords and more than 30 million stolen cookies. Many of those cookies were tracking or non-sensitive cookies rather than high-value credentials.

- Advertisement -

Researchers also found a single admin account using an Apple M3 machine with English and Russian settings. An operational mistake in mid-July 2025 — failing to use a VPN — revealed a real IP tied to TRK Cable TV, suggesting the operator is a lone actor in an Eastern European, Russian-speaking area.

CyberArk noted that weaknesses in the panel and cookie handling exposed customer data and that similar flaws in other malware services could let researchers and law enforcement gather actionable intelligence, as stated in their report.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Gerber: Tesla “Worthless” Without SpaceX Merger

Investor Ross Gerber claims Tesla is "worthless" without a merger with SpaceX, a deal...

GAO Urges FDIC to Coordinate on Blockchain Risks

The U.S. Government Accountability Office urged the FDIC to coordinate with other agencies to...

Einhorn Invests In StubHub, Shares Jump On Bet

Hedge fund manager David Einhorn’s DME Capital initiated a new position in StubHub Holdings...

SpaceX Hits $2.52T Market Cap, 6th Largest Globally

SpaceX stock surged nearly 20% on Monday, elevating its market cap to $2.52 trillion...

UFC Fighters Paid Bonuses in Trump-Linked Stablecoin

Fighters at the UFC event on the White House lawn received up to $250,000...

Must Read

8 Best Crypto Debit Cards For Spending Your Digital Tokens

What are | How we chose | Best crypto debit cards | Binance Card? | FAQ | Final WordsCrypto debit cards have transformed how...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading