The post ModStealer Malware Targets Crypto Wallets Across Platforms appeared on BitcoinEthereumNews.com. A newly-discovered malware called ModStealer is targeting crypto users across macOS, Windows and Linux systems, posing risks to wallets and access credentials. Apple-focused security firm Mosyle uncovered the malware, saying it remained completely undetected by major antivirus engines for almost a month after being uploaded to VirusTotal, an online platform that analyzes files to detect malicious content, 9to5mac reported. Mosyle said ModStealer is designed to extract data, with pre-loaded code that steals private keys, certificates, credential files and browser-based wallet extensions. The security researchers found targeting logic for different wallets, including extensions on Safari and Chromium-based browsers.  The security firm said the malware persists on macOS by abusing the system to register as a background agent. The team said the server is hosted in Finland but believes the infrastructure is routed through Germany to mask the operators’ origin. Security firm warns of fake job ads The malware is reportedly being distributed through fake job recruitment ads, a tactic that has been increasingly used to target Web3 developers and builders.  Once users install the malicious package, ModStealer embeds itself into the system and operates in the background. It captures data from the clipboard, takes screenshots and executes remote commands.  Stephen Ajayi, DApp and AI audit technical lead at blockchain security firm Hacken, told Cointelegraph that malicious recruitment campaigns using fraudulent “test tasks” as a malware delivery mechanism are becoming increasingly common. He warned developers to take extra precautions when asked to download files or complete assessments.  “Developers should validate the legitimacy of recruiters and associated domains,” Ajayi told Cointelegraph. “Request that assignments be shared via public repositories, and open any task exclusively in a disposable virtual machine with no wallets, SSH keys or password managers.” Emphasizing the importance of compartmentalizing sensitive assets, Ajayi advised teams to maintain a strict separation between… The post ModStealer Malware Targets Crypto Wallets Across Platforms appeared on BitcoinEthereumNews.com. A newly-discovered malware called ModStealer is targeting crypto users across macOS, Windows and Linux systems, posing risks to wallets and access credentials. Apple-focused security firm Mosyle uncovered the malware, saying it remained completely undetected by major antivirus engines for almost a month after being uploaded to VirusTotal, an online platform that analyzes files to detect malicious content, 9to5mac reported. Mosyle said ModStealer is designed to extract data, with pre-loaded code that steals private keys, certificates, credential files and browser-based wallet extensions. The security researchers found targeting logic for different wallets, including extensions on Safari and Chromium-based browsers.  The security firm said the malware persists on macOS by abusing the system to register as a background agent. The team said the server is hosted in Finland but believes the infrastructure is routed through Germany to mask the operators’ origin. Security firm warns of fake job ads The malware is reportedly being distributed through fake job recruitment ads, a tactic that has been increasingly used to target Web3 developers and builders.  Once users install the malicious package, ModStealer embeds itself into the system and operates in the background. It captures data from the clipboard, takes screenshots and executes remote commands.  Stephen Ajayi, DApp and AI audit technical lead at blockchain security firm Hacken, told Cointelegraph that malicious recruitment campaigns using fraudulent “test tasks” as a malware delivery mechanism are becoming increasingly common. He warned developers to take extra precautions when asked to download files or complete assessments.  “Developers should validate the legitimacy of recruiters and associated domains,” Ajayi told Cointelegraph. “Request that assignments be shared via public repositories, and open any task exclusively in a disposable virtual machine with no wallets, SSH keys or password managers.” Emphasizing the importance of compartmentalizing sensitive assets, Ajayi advised teams to maintain a strict separation between…

ModStealer Malware Targets Crypto Wallets Across Platforms

3 min read

A newly-discovered malware called ModStealer is targeting crypto users across macOS, Windows and Linux systems, posing risks to wallets and access credentials.

Apple-focused security firm Mosyle uncovered the malware, saying it remained completely undetected by major antivirus engines for almost a month after being uploaded to VirusTotal, an online platform that analyzes files to detect malicious content, 9to5mac reported.

Mosyle said ModStealer is designed to extract data, with pre-loaded code that steals private keys, certificates, credential files and browser-based wallet extensions. The security researchers found targeting logic for different wallets, including extensions on Safari and Chromium-based browsers. 

The security firm said the malware persists on macOS by abusing the system to register as a background agent. The team said the server is hosted in Finland but believes the infrastructure is routed through Germany to mask the operators’ origin.

Security firm warns of fake job ads

The malware is reportedly being distributed through fake job recruitment ads, a tactic that has been increasingly used to target Web3 developers and builders. 

Once users install the malicious package, ModStealer embeds itself into the system and operates in the background. It captures data from the clipboard, takes screenshots and executes remote commands. 

Stephen Ajayi, DApp and AI audit technical lead at blockchain security firm Hacken, told Cointelegraph that malicious recruitment campaigns using fraudulent “test tasks” as a malware delivery mechanism are becoming increasingly common. He warned developers to take extra precautions when asked to download files or complete assessments. 

“Developers should validate the legitimacy of recruiters and associated domains,” Ajayi told Cointelegraph. “Request that assignments be shared via public repositories, and open any task exclusively in a disposable virtual machine with no wallets, SSH keys or password managers.”

Emphasizing the importance of compartmentalizing sensitive assets, Ajayi advised teams to maintain a strict separation between their development environments and wallet storage. 

“A clear separation between the development environment ‘dev box’ and wallet environment ‘wallet box’ is essential,” he told Cointelegraph.

Related: Failed NPM exploit highlights looming threat to crypto security: Exec

Hacken security lead shares practical steps for users

Ajayi also stressed the importance of basic wallet hygiene and endpoint hardening to defend against threats like Modstealer.

“Use hardware wallets and always confirm transaction addresses on the device display, verifying at least the first and last six characters before approving,” he told Cointelegraph.

Ajayi advised users to maintain a dedicated, locked-down browser profile or a separate device exclusively for wallet activity, interacting with only the trusted wallet extensions.

For account protection, he recommended offline storage of seed phrases, multifactor authentication and the use of FIDO2 passkeys when possible. 

Magazine: Thailand’s ‘Big Secret’ crypto hack, Chinese developer’s RWA tokens: Asia Express

Source: https://cointelegraph.com/news/modstealer-malware-crypto-wallets-fake-job-ads?utm_source=rss_feed&utm_medium=feed&utm_campaign=rss_partner_inbound

Market Opportunity
null Logo
null Price(null)
--
----
USD
null (null) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

USDT Transfer Stuns Market: $238 Million Whale Movement to Bitfinex Reveals Critical Patterns

USDT Transfer Stuns Market: $238 Million Whale Movement to Bitfinex Reveals Critical Patterns

BitcoinWorld USDT Transfer Stuns Market: $238 Million Whale Movement to Bitfinex Reveals Critical Patterns In a stunning development that captured global cryptocurrency
Share
bitcoinworld2026/02/06 21:45
The market value of NFTs has fallen back to pre-2021 levels, close to $1.5 billion.

The market value of NFTs has fallen back to pre-2021 levels, close to $1.5 billion.

PANews reported on February 6th, citing Cointelegraph, that the global NFT market capitalization has fallen below $1.5 billion, returning to pre-2021 levels. This
Share
PANews2026/02/06 21:13
Eminem’s Newest Album Becomes His Latest To Make It To A Notable Landmark

Eminem’s Newest Album Becomes His Latest To Make It To A Notable Landmark

The post Eminem’s Newest Album Becomes His Latest To Make It To A Notable Landmark appeared on BitcoinEthereumNews.com. Eminem’s The Death of Slim Shady (Coup de Grâce) celebrates one year on the U.K.’s Official Hip Hop and R&B Albums chart, climbing to No. 7 in its fifty-second week. UNSPECIFIED – JANUARY 01: Photo of EMINEM (Photo by Sal Idriss/Redferns) Redferns In the United Kingdom, Eminem is a fixture on the Official Hip Hop and R&B Albums chart. That tally ranks the bestselling full-lengths and EPs that can be classified by the Official Charts Company as hip-hop, rap, R&B or some other subgenre connected to those styles. The American superstar almost always claims multiple positions on the 40-spot roster, as he remains one of hip-hop’s most commercially successful artists, even decades after his debut. Eminem’s latest album turns one on the genre-specific tally, becoming his latest win to celebrate such a birthday. Eminem’s Album Reaches Its First Year Eminem’s The Death of Slim Shady (Coup de Grâce) reaches 52 weeks on the Official Hip Hop and R&B Albums chart. As it makes it to its first year on the tally, the set rises from No. 8 to No. 7. Eminem’s History with The Death of Slim Shady The Death of Slim Shady (Coup de Grâce) debuted at No. 1 on the Official Hip Hop and R&B Albums chart in July 2024. So far, in the 52 weeks it has spent somewhere on the tally, the set has racked up six stays at No. 1 and 29 inside the top 10, including the most recent three periods. Eminem’s Years-Long-Charters 13 of the 20 projects Eminem has sent to the Official Hip Hop and R&B Albums chart have lived on the list for at least a year. The longest-running of the bunch is Curtain Call: The Hits, his hugely successful compilation. That set is now up to 924 stays on the…
Share
BitcoinEthereumNews2025/09/20 00:58