Bitcoin is down -2.99% in the last 24 hours

Browse through the current market rates for various cryptocurrencies from your dashboard.

Bitmap Copy 3
Bitcoin

BTC

$89,338.07

-0.31% 1h

noun-5629767
Max Supply
21,000,000
noun-3235386
Circulating Supply
19,958,221
noun-7899443
Volume

24h

$61,140,145,510.85

6.22% 1h

Shape
Market Dominance
58.70%
Shape
Price Change 90D
-19.59%

This Invisible ‘ModStealer’ Is Targeting Your Browser-Based Crypto Wallets

A new strain of malware purpose-built to steal crypto wallet data is slipping past every major antivirus engine, according to Apple device security firm Mosyle.

Dubbed ModStealer, the infostealer has been live for nearly a month without detection by virus scanners. Mosyle researchers say the malware is being distributed through malicious recruiter ads targeting developers and uses a heavily obfuscated NodeJS script to bypass signature-based defenses.

That means the malware’s code has been scrambled and layered with tricks that make it unreadable to signature-based antivirus tools. Since these defenses rely on spotting recognizable code “patterns,” the obfuscation hides them, allowing the script to execute without detection.

In practice, this lets attackers slip malicious instructions into a system while bypassing traditional security scans that would usually catch simpler, unaltered code.

Unlike most Mac-focused malware, ModStealer is cross-platform, hitting Windows and Linux environments as well. Its primary mission is that of data exfiltration, and the code is presumed to include pre-loaded instructions to target 56 browser wallet extensions designed to extract private keys, credentials, and certificates.

The malware also supports clipboard hijacking, screen capture, and remote code execution, giving attackers the ability to seize near-total control of infected devices. On macOS, persistence is achieved via Apple’s launching tool, embedding itself as a LaunchAgent.

Mosyle states that the build aligns with the profile of “Malware-as-a-Service,” where developers sell ready-made tools to affiliates with limited technical expertise. The model has driven a surge in infostealers this year, with Jamf reporting a 28% rise in 2025 alone.

The discovery comes on the heels of recent npm-focused attacks where malicious packages like colortoolsv2 and mimelib2 used Ethereum smart contracts to conceal second-stage malware. In both cases, attackers leveraged obfuscation and trusted developer infrastructure to bypass detection.

ModStealer extends this pattern beyond package repositories, showing how cybercriminals are escalating their techniques across ecosystems to compromise developer environments and directly target crypto wallets.

Related Posts

XRP Ledger’s Utility Profile Draws Fresh Attention From Ripple Executive

The XRP Ledger is increasingly framed as purpose-built infrastructure for high-volume financial settlement, signaling its expanding role in...

SEC Crypto Task Force Releases Surveillance Roundtable Agenda

The SEC’s upcoming financial surveillance roundtable spotlights how rapidly evolving crypto privacy tools could reshape oversight while raising...

UAE’s Mashreq Capital Unveils Multi-Asset Fund With Bitcoin Allocation

Mashreq Capital has launched a new multi-asset investment product that provides regulated exposure to Bitcoin ( BTC) for...

Join the Newsletter

noun-7811267

Strong AES 256-bit encryption

noun-7335232

Operating since 2023

noun-7776734

24/7 dedicated client care

Copyright © 2025 by Sable Venture Capital Inc. | All Rights Reserved