API Download the RootData App

The new malware ModStealer can bypass antivirus software to steal cryptocurrency wallets

Sep 12, 2025 13:31:53

Share to

ChainCatcher news, according to market reports, security company Mosyle has disclosed a cross-platform malware called ModStealer, which can disguise itself as a background assistant program to bypass mainstream antivirus detection, specifically targeting browser cryptocurrency wallet data on Windows, Linux, and macOS systems.

The software spreads by masquerading as job advertisements, targeting developers with an installed Node.js environment. ModStealer can run automatically and collect wallet extensions, system credentials, and digital certificates, subsequently uploading the data to a remote C2 server. Security experts warn that this malware poses a direct threat to cryptocurrency users and platforms, potentially leading to the leakage of private keys, recovery phrases, and API keys, triggering large-scale on-chain attacks.

Recent Fundraising

More
-- Dec 26
$1M Dec 25
$35M Dec 24

New Tokens

More
Dec 23
Dec 20

Latest Updates on 𝕏

More