The new malware ModStealer can bypass antivirus software to steal cryptocurrency wallets
Sep 12, 2025 13:31:53
ChainCatcher news, according to market reports, security company Mosyle has disclosed a cross-platform malware called ModStealer, which can disguise itself as a background assistant program to bypass mainstream antivirus detection, specifically targeting browser cryptocurrency wallet data on Windows, Linux, and macOS systems.
The software spreads by masquerading as job advertisements, targeting developers with an installed Node.js environment. ModStealer can run automatically and collect wallet extensions, system credentials, and digital certificates, subsequently uploading the data to a remote C2 server. Security experts warn that this malware poses a direct threat to cryptocurrency users and platforms, potentially leading to the leakage of private keys, recovery phrases, and API keys, triggering large-scale on-chain attacks.
Latest News
ChainCatcher
Dec 28, 2025 13:00:00
ChainCatcher
Dec 28, 2025 12:30:44
ChainCatcher
Dec 28, 2025 12:13:17
ChainCatcher
Dec 28, 2025 11:43:53
ChainCatcher
Dec 28, 2025 11:30:26


