MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Undetectable “ModStealer” malware hijacks crypto wallets on macOS and Windows
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$70,277.00-0.13%
  • ethereumEthereum(ETH)$2,106.700.71%
  • tetherTether(USDT)$1.000.00%
  • rippleXRP(XRP)$1.440.72%
  • binancecoinBNB(BNB)$636.89-0.46%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$86.900.24%
  • tronTRON(TRX)$0.2786460.24%
  • dogecoinDogecoin(DOGE)$0.096282-0.36%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.031.33%
Crypto NewsBlockchain

Undetectable “ModStealer” malware hijacks crypto wallets on macOS and Windows

rahulbadiyafad150c105
Last updated: September 12, 2025 4:29 pm
rahulbadiyafad150c105
Published: 5 months ago
Share

ModStealer, a newly identified malware strain, has been quietly stealing cryptocurrency by targeting wallet extensions on macOS, Windows and Linux systems, security firm Mosyle warns.

Mosyle — an Apple-focused device-management and security platform — discovered the threat after spotting that ModStealer had gone undetected by major antivirus engines for weeks. “The malware has remained invisible to all major antivirus engines since first appearing on VirusTotal nearly a month ago,” the company said in a report shared with 9to5Mac.

Although Mosyle usually focuses on macOS threats, its analysis shows ModStealer is cross-platform by design and can run in Windows and Linux environments as well. The researchers also observed indicators that the malware may be offered as Malware-as-a-Service, a model that lets less technically skilled criminals deploy prebuilt malware in exchange for fees or a cut of profits.

Mosyle traced initial distribution to malicious job-recruiter ads that specifically target developers. The attackers embed a heavily obfuscated JavaScript payload that runs inside Node.js — an environment commonly used by developers and often granted elevated permissions during testing and deployment — making it both stealthy and effective at gaining access to sensitive developer resources.

Once installed, ModStealer functions as an infostealer: it’s preloaded to target at least 56 browser wallet extensions (including Safari) to harvest private keys. The malware can also read clipboard contents, take screenshots, and execute remote commands — capabilities Mosyle says could allow attackers “nearly complete control over infected devices.”

On macOS, ModStealer uses the system’s launchctl utility to persist by disguising itself as a legitimate background service so it runs at startup. Mosyle further reported that stolen data is forwarded to a server in Finland that connects to infrastructure in Germany, likely an attempt to hide the operators’ true location.

Mosyle warned that signature-based antivirus tools struggle to spot such highly obfuscated threats and urged developers not to rely solely on those protections.

“[..] Signature-based protections alone are not enough. Continuous monitoring, behavior-based defenses, and awareness of emerging threats are essential to stay ahead of adversaries.”

New dangers for Mac and Windows crypto users

With global cryptocurrency adoption accelerating, cybercriminals are intensifying efforts to design sophisticated attacks aimed at draining digital assets. ModStealer is just one of several threats drawing attention.

Earlier this month, analysts at ReversingLabs flagged an open-source malware hidden within Ethereum smart contracts, capable of deploying malicious payloads against unsuspecting crypto users.

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Altcoins Peak as BTC Dominance Falls, Remittix Among Emerging Tokens Outpacing the Rest After 450% Gains
GameStop shutters more stores as retail apocalypse continues
Stablecoins Over Speculation: Why Wall Street Pays Attention – Crypto Economy
Top Crypto Coins To Buy Now As APEMARS ($APRZ) Gains Momentum: These Meme Coins Could Explode After FOMC – The Bit Journal
XRP Ties with ETH for Second in Kaiko’s Q3 2025 Crypto Asset Ranking · Cardano Feed
TAGGED:AltcoinBlockchainCrypto WalletcryptocurrenciesmacOSMalwareModStealerWindows

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article PowerDMARC is Exhibiting at ScaleCon2025 in New Orleans
Next Article OP Price Prediction: Targeting $2.20-$2.50 by October 2025 Despite Near-Term Consolidation
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d