BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

ModStealer Malware Evades Detection, Targets Crypto Wallets

Malware spreads through fake recruiter ads aimed at developers.

  • New Malware called ModStealer targets crypto wallets on Windows, macOS, and Linux.
  • ModStealer evades common antivirus detection and steals sensitive data.
  • It disguises itself as a helper program and sends stolen details to remote servers.
  • Experts warn it poses a serious risk to crypto users and digital asset platforms.

A newly identified malware called ModStealer is actively targeting cryptocurrency users by stealing data from browser-based wallet extensions on computers running Windows, Linux, and macOS. The malware was discovered in early September after operating undetected for nearly a month and is distributed using fake job recruiter ads designed to reach developers.

- Advertisement -

According to security company Mosyle, the malware is spread through misleading advertisements that specifically target developers likely to have Node.js environments already set up. These ads contain obfuscated code, helping ModStealer avoid being flagged by most major antivirus tools. Once downloaded, the malware searches the infected system for browser wallet extensions, login credentials, and digital certificates.

Shān Zhang, the chief information security officer at blockchain security group Slowmist, stated to Decrypt that ModStealer works across multiple operating systems and “evades detection by mainstream antivirus solutions and poses significant risks to the broader digital asset ecosystem.” Once running, ModStealer sends all stolen information to command and control (C2) servers operated by attackers. C2 servers are systems cybercriminals use to coordinate and manage malware activities remotely.

On macOS devices, ModStealer persists by setting itself up as a background helper application that launches on startup. Signs of infection include the presence of a hidden file named “.sysupdater.dat” and unusual connections to suspicious servers. Zhang explained that its use of common persistence methods combined with strong code obfuscation help it remain undetected by signature-based security tools.

This discovery comes just after Ledger CTO Charles Guillemet warned of another breach involving an NPM developer account compromise that could have replaced crypto wallet addresses in user transactions. Although that attack was stopped early, Guillemet said packages had been set up to target Ethereum, Solana, and other blockchains.

- Advertisement -

Zhang cautioned that “private keys, seed phrases, and exchange API keys may be compromised, resulting in direct asset loss” for users. For the industry, he added, “mass theft of browser extension wallet data could trigger large-scale on-chain exploits.”

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

SanDisk, Western Digital price targets lifted on AI demand

Cantor Fitzgerald analyst C.J. Muse significantly raised price targets for SanDisk (SNDK) and Western...

Robinhood phishing scam used authentic emails to attack

Highly convincing phishing emails were sent to Robinhood customers this weekend, appearing to come...

Checkmarx Data Leaked on Dark Web Following Attack

Checkmarx confirms stolen data from its GitHub repository was published on the dark web.The...

Strategy Acquires 3,273 Bitcoin, Holds 818,334 BTC

Strategy purchased an additional 3,273 Bitcoin for approximately $255 million, increasing its total holdings...

China Orders Meta to Unwind $2B AI Startup Deal

Chinese regulators have ordered Meta to fully unwind its $2 billion acquisition of AI...

Must Read

5 Best Hacking eBooks for Beginners

In this article we present the 5 Best Hacking eBooks for beginners as ranked by our editorial teamWelcome to the world of hacking, where...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading