Skip to content

Bitcoin Malware Drains Crypto Wallets Undetected

New Malware ModStealer Threatens Crypto Wallet Security

  • ModStealer, a new malware strain, can bypass antivirus checks and target crypto wallets on Windows, Linux, and macOS systems.
  • The malware is distributed through fake job recruiter ads aimed at developers with Node.js environments.
  • It specifically targets browser-based crypto wallet extensions, system credentials, and digital certificates to exfiltrate data to remote C2 servers.
  • On macOS, ModStealer uses a persistence method to run automatically by disguising itself as a background helper program.

ModStealer poses a significant threat to the digital asset ecosystem by evading detection from mainstream antivirus solutions. Its ability to operate across multiple platforms makes it particularly dangerous for crypto users and platforms alike.

The discovery of ModStealer highlights the ongoing risks faced by the crypto industry, emphasizing the need for vigilance against sophisticated cyber threats that could lead to mass theft of browser extension wallet data and large-scale on-chain exploits. (Source)

Share