Undetectable Malware ’ModStealer’ Targets Crypto Wallets Across Multiple Platforms
A newly discovered malware strain, ModStealer, has been evading antivirus detection while stealing data from cryptocurrency wallets on Windows, Linux, and macOS systems. Distributed through fake job recruiter ads targeting developers, the malware leverages obfuscated code to disguise itself as a background helper, making it particularly dangerous for crypto users.
Security firm Mosyle disclosed the threat, noting that ModStealer had remained undetected by major antivirus engines for nearly a month. The malware's delivery method—posing as Node.js-related job ads—was strategically chosen to target developers likely to have pre-installed crypto wallet environments.
Shān Zhang, CISO at Slowmist, emphasized the malware's unique risks: "ModStealer stands out for its multi-platform support and stealthy 'zero-detection' execution chain." The threat underscores growing security challenges in the digital asset ecosystem as attackers refine their tactics.