New ’ModStealer’ Malware Evades Detection to Target Crypto Wallets Across Platforms
A sophisticated malware strain named ModStealer has been operating undetected for nearly a month, bypassing all major antivirus engines. The threat, identified by Apple security firm Mosyle, specifically targets browser-based cryptocurrency wallets through obfuscated NodeJS scripts distributed via fake recruiter ads.
ModStealer employs advanced code scrambling techniques to evade signature-based detection systems. Its cross-platform capabilities allow it to infect Windows, Linux, and macOS devices equally. The malware focuses on data exfiltration, with built-in functionality to target 56 browser wallet extensions for private keys, credentials, and certificates.
Beyond wallet theft, ModStealer enables clipboard hijacking, screen capture, and remote code execution - granting attackers near-total control of compromised devices. The malware's persistence mechanisms on macOS suggest long-term infiltration capabilities.