The new malware ModStealer can bypass antivirus software to steal cryptocurrency wallets
Sep 12, 2025 13:31:53
ChainCatcher news, according to market reports, security company Mosyle has disclosed a cross-platform malware called ModStealer, which can disguise itself as a background assistant program to bypass mainstream antivirus detection, specifically targeting browser cryptocurrency wallet data on Windows, Linux, and macOS systems.
The software spreads by masquerading as job advertisements, targeting developers with an installed Node.js environment. ModStealer can run automatically and collect wallet extensions, system credentials, and digital certificates, subsequently uploading the data to a remote C2 server. Security experts warn that this malware poses a direct threat to cryptocurrency users and platforms, potentially leading to the leakage of private keys, recovery phrases, and API keys, triggering large-scale on-chain attacks.
Latest News
ChainCatcher
Dec 27, 2025 20:36:49
ChainCatcher
Dec 27, 2025 20:23:55
ChainCatcher
Dec 27, 2025 20:05:50
ChainCatcher
Dec 27, 2025 19:08:34
ChainCatcher
Dec 27, 2025 17:59:58


