MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: New ModStealer malware targets crypto wallets across operating systems
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$75,084.00-1.64%
  • ethereumEthereum(ETH)$2,311.09-2.14%
  • tetherTether(USDT)$1.000.01%
  • rippleXRP(XRP)$1.42-1.47%
  • binancecoinBNB(BNB)$620.11-2.21%
  • usd-coinUSDC(USDC)$1.00-0.01%
  • solanaSolana(SOL)$84.66-2.90%
  • tronTRON(TRX)$0.3331101.62%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.041.31%
  • dogecoinDogecoin(DOGE)$0.093760-3.04%
Blockchain Security

New ModStealer malware targets crypto wallets across operating systems

Last updated: September 12, 2025 6:20 pm
Published: 7 months ago
Share

Hacken’s Stephen Ajayi told Cointelegraph that basic wallet hygiene and endpoint hardening are essential to defend against threats like ModStealer.

A newly-discovered malware called ModStealer is targeting crypto users across macOS, Windows and Linux systems, posing risks to wallets and access credentials.

Apple-focused security firm Mosyle uncovered the malware, saying it remained completely undetected by major antivirus engines for almost a month after being uploaded to VirusTotal, an online platform that analyzes files to detect malicious content, 9to5mac reported.

Mosyle said ModStealer is designed to extract data, with pre-loaded code that steals private keys, certificates, credential files and browser-based wallet extensions. The security researchers found targeting logic for different wallets, including extensions on Safari and Chromium-based browsers.

The security firm said the malware persists on macOS by abusing the system to register as a background agent. The team said the server is hosted in Finland but believes the infrastructure is routed through Germany to mask the operators’ origin.

The malware is reportedly being distributed through fake job recruitment ads, a tactic that has been increasingly used to target Web3 developers and builders.

Once users install the malicious package, ModStealer embeds itself into the system and operates in the background. It captures data from the clipboard, takes screenshots and executes remote commands.

Stephen Ajayi, DApp and AI audit technical lead at blockchain security firm Hacken, told Cointelegraph that malicious recruitment campaigns using fraudulent “test tasks” as a malware delivery mechanism are becoming increasingly common. He warned developers to take extra precautions when asked to download files or complete assessments.

“Developers should validate the legitimacy of recruiters and associated domains,” Ajayi told Cointelegraph. “Request that assignments be shared via public repositories, and open any task exclusively in a disposable virtual machine with no wallets, SSH keys or password managers.”

Emphasizing the importance of compartmentalizing sensitive assets, Ajayi advised teams to maintain a strict separation between their development environments and wallet storage.

“A clear separation between the development environment ‘dev box’ and wallet environment ‘wallet box’ is essential,” he told Cointelegraph.

Related: Failed NPM exploit highlights looming threat to crypto security: Exec

Ajayi also stressed the importance of basic wallet hygiene and endpoint hardening to defend against threats like Modstealer.

“Use hardware wallets and always confirm transaction addresses on the device display, verifying at least the first and last six characters before approving,” he told Cointelegraph.

Ajayi advised users to maintain a dedicated, locked-down browser profile or a separate device exclusively for wallet activity, interacting with only the trusted wallet extensions.

For account protection, he recommended offline storage of seed phrases, multifactor authentication and the use of FIDO2 passkeys when possible.

Read more on Cointelegraph

This news is powered by Cointelegraph Cointelegraph

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Digital Asset Analytics Across Borders — Bridgehold Brings Transparency to Blockchain Data – South Africa Today
Crystal Intelligence shares top insights from the frontlines of the battle against crypto scams
Mutuum Finance (MUTM) Named the Next 100x Crypto While Cardano (ADA) Climbs
No crying in the casino: XPL bug hits Aster, Hypervault rug pull suspected
Tron Strengthens Its Network Through Surprise Partnership With Kraken

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article New ‘sophisticated’ phishing exploit drains $3M in USDC from multi-sig wallet | Ethereum Tokens | CryptoRank.io
Next Article New ‘sophisticated’ phishing exploit drains $3M in USDC from multi-sig wallet
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d