-
Back to menu
Prices
-
Back to menu
-
Back to menu
Indices -
Back to menu
Research
-
Back to menu
Events -
Back to menu
Sponsored
-
Back to menu
Videos -
Back to menu
-
Back to menu
-
Back to menu
Webinars
Select Language
The code includes pre-loaded instructions to target 56 browser wallet extensions and is designed to extract private keys, credentials, and certificates.
By Shaurya Malwa|Edited by Parikshit Mishra
Updated Sep 12, 2025, 7:21 a.m. Published Sep 12, 2025, 6:44 a.m.

- A new malware strain called ModStealer is evading major antivirus engines and targeting crypto wallet data.
- ModStealer uses obfuscated NodeJS scripts to bypass signature-based defenses and is distributed through malicious recruiter ads.
- The malware affects Windows, Linux, and macOS, supporting data exfiltration, clipboard hijacking, and remote code execution.
A new strain of malware purpose-built to steal crypto wallet data is slipping past every major antivirus engine, according to Apple device security firm Mosyle.
Dubbed ModStealer, the infostealer has been live for nearly a month without detection by virus scanners. Mosyle researchers say the malware is being distributed through malicious recruiter ads targeting developers and uses a heavily obfuscated NodeJS script to bypass signature-based defenses.
STORY CONTINUES BELOW
That means the malware’s code has been scrambled and layered with tricks that make it unreadable to signature-based antivirus tools. Since these defenses rely on spotting recognizable code “patterns,” the obfuscation hides them, allowing the script to execute without detection.
In practice, this lets attackers slip malicious instructions into a system while bypassing traditional security scans that would usually catch simpler, unaltered code.
Unlike most Mac-focused malware, ModStealer is cross-platform, hitting Windows and Linux environments as well. Its primary mission is that of data exfiltration, and the code is presumed to include pre-loaded instructions to target 56 browser wallet extensions designed to extract private keys, credentials, and certificates.
The malware also supports clipboard hijacking, screen capture, and remote code execution, giving attackers the ability to seize near-total control of infected devices. On macOS, persistence is achieved via Apple’s launching tool, embedding itself as a LaunchAgent.
Mosyle states that the build aligns with the profile of “Malware-as-a-Service,” where developers sell ready-made tools to affiliates with limited technical expertise. The model has driven a surge in infostealers this year, with Jamf reporting a 28% rise in 2025 alone.
The discovery comes on the heels of recent npm-focused attacks where malicious packages like colortoolsv2 and mimelib2 used Ethereum smart contracts to conceal second-stage malware. In both cases, attackers leveraged obfuscation and trusted developer infrastructure to bypass detection.
ModStealer extends this pattern beyond package repositories, showing how cybercriminals are escalating their techniques across ecosystems to compromise developer environments and directly target crypto wallets.
More For You
By Sam Reynolds|Edited by Parikshit Mishra
1 hour ago
WLFI edges higher on the week as holders rally behind a deflationary strategy to counter post-launch weakness.
What to know:
- World Liberty Financial’s token, WLFI, remains stable after a community-approved plan to use liquidity fees for a buyback-and-burn mechanism.
- WLFI is trading near $0.20, with a market cap of $5.4 billion and daily trading volumes around $480 million.
- The proposal to burn tokens received overwhelming support, with 99.48% of votes in favor, aiming to create a deflationary model similar to Ethereum.