BTCC / BTCC Square / Global Cryptocurrency /
ModStealer Malware Targets Cryptocurrency Users via Fake Job Ads

ModStealer Malware Targets Cryptocurrency Users via Fake Job Ads

Published:
2025-09-13 15:46:03
18
3
BTCCSquare news:

A newly discovered malware strain, ModStealer, has been targeting cryptocurrency users by spreading through fake job recruitment ads. The cross-platform threat, undetected by antivirus tools for nearly a month, specifically aims to steal sensitive data from 56 browser wallet extensions, including private keys and account credentials.

Developed with advanced obfuscation techniques, ModStealer employs JavaScript to evade detection while executing remote code, clipboard hijacking, and screen capture functionalities. Its primary focus is on draining cryptocurrency wallets, but it also harvests certificates and login details from infected macOS, Windows, and Linux systems.

The malware's distribution chain includes a sophisticated NPM supply chain attack using spoofed emails to redirect blockchain transactions. Security firm Mosyle warns that the threat actor behind ModStealer demonstrates a concerning level of precision in exploiting crypto holders.

|Square

Get the BTCC app to start your crypto journey

Get started today Scan to join our 100M+ users