Crypto Users Face Danger from New ModStealer Malware

TheCryptoTimesPublicado em 2025-09-12Última atualização em 2025-09-12

While the crypto industry is going through various security breaches, ModStealer, a new infostealer malware, is targeting crypto users on macOS, Windows, and Linux systems. Experts note that this malware can steal information on crypto wallets and access credentials of users. 

According to information from 9to5mac, Apple-focused security company Mosyle found the malware, which even major antivirus engines failed to catch for almost a month after it was uploaded to VirusTotal, an online service that checks files for harmful content.

The report cites that the ModStealer is being delivered to victims through malicious job postings, specifically targeting developers. Using heavily obfuscated JavaScript files written with NodeJS, the malware remains completely undetectable by signature-based defenses. 

“The malware’s main goal is data exfiltration, with a particular focus on cryptocurrency wallets, credential files, configuration details, and certificates,” Mosyle said. The security researchers also found targeting logic for different wallets, such as extensions for Safari and Chromium-based browsers. 

Malware’s perplexing infrastructure

The security company said that the malware stays on macOS by using the system to register as a background agent. While its server seems hosted in Finland, it is believed that the infrastructure is routed through Germany to hide where the operators are from.

“For security professionals, developers, and end users alike, this serves as a stark reminder that signature-based protections alone are not enough. Continuous monitoring, behavior-based defenses, and awareness of emerging threats are essential to stay ahead of adversaries,” Mosyle warns.

On macOS, the malware stays on a victim’s Mac for a long time and is hard to find by using Apple’s own launchctl tool to install itself as a LaunchAgent. From there, it watches what people do and sends sensitive data to a server far away.

Mosyle thinks that the ModStealer fits the description of Malware-as-a-Service (MaaS). This is where people who make malware make and sell harmful packages to affiliates. This kind of business model has become more and more popular among cybercriminal gangs, especially when it comes to spreading infostealers. 

Rise in Crypto Related Hacks 

Crypto hacks have been on the rise for the past few months. PeckShield, a blockchain security firm, says that the hackers stole over $142 million in 17 attacks last month. The amount is 27.2% higher than that of $111.6 million in June 2025.

Also Read: Radiant Hacker Moves $26.7 Million in Stolen Funds to Ethereum


Mobile Only ImageMobile Only Image

Leituras Relacionadas

Google's 'Reasoning King' Also Departs for Meta, Originally Recruited by Fei-Fei Li

"Google's 'King of Reasoning' Leaves for Meta, Quietly Departing After Over Eight Years. Denny Zhou, a key figure behind Google's AI reasoning advancements including work showcased by CEO Sundar Pichai, has joined Meta's MSL as a research scientist. His low-profile move, discovered via a LinkedIn update, occurred months before the high-profile departures of Noam Shazeer to OpenAI and Nobel laureate John Jumper to Anthropic. Zhou was originally recruited to Google by Fei-Fei Li's China center initiative after nearly 11 years at Microsoft. This is part of a significant talent drain at Google, with top researchers like Shazeer (co-author of the Transformer paper) and Jumper (AlphaFold lead) recently leaving for rivals. Reports suggest internal friction is a contributing factor, particularly around Google's strategic shift. The company has reportedly formed a high-priority 'AI Coding Strike Team,' involving co-founder Sergey Brin, to urgently bridge the gap in AI coding agents, potentially reallocating resources and focus away from other research directions like DeepMind's 'world model' AGI approach. This pivot towards commercially-proven coding applications may have influenced departures, as hinted by Shazeer's comment about his compute allocation being given to another team. Meanwhile, Meta continues to bolster its team, also recently hiring UC Berkeley professor and 'security godmother' Dawn Song, along with her startup Virtue AI team, as a VP of AI research."

marsbitHá 59m

Google's 'Reasoning King' Also Departs for Meta, Originally Recruited by Fei-Fei Li

marsbitHá 59m

How Did Hundreds of Billions of Dollars Flow into SpaceX After Its Index Inclusion on June 26th? Will SpaceX Experience a Massive Price Surge?

Will SpaceX ($SPCX) stock surge when billions in passive index fund money flows in on the effective date? A common retail investor belief is that a massive wave of buying will hit on July 6th, when SpaceX joins the Nasdaq-100, potentially causing a huge price spike. However, the reality is far more complex and less dramatic. The anticipated billions are not controlled by a single entity but are spread across hundreds of passive fund managers (e.g., BlackRock, Vanguard) whose sole mandate is to minimize "tracking error." They aim to buy shares at prices as close as possible to the index's closing price on the effective date, not to aggressively drive the price up. There are two key index inclusion scripts: 1) For the Russell US Index (effective June 26th at close), buying is compressed into the final minutes via Market-On-Close (MOC) orders. 2) For the Nasdaq-100 (announced June 26th, effective July 6th), a 10-day window creates a layered game. Arbitrage funds buy early, betting on selling to passive funds later. Some index funds "front-run" by accumulating shares gradually before the deadline. The bulk of passive funds execute large MOC orders at the July 6th close, often trading directly with arbitrageurs. A critical wildcard is SpaceX's limited free float due to a standard 180-day post-IPO lockup. To avoid causing a massive price spike by competing for scarce shares on the open market, large funds will likely use off-exchange methods: 1) Negotiating large block trades (over-the-counter) with major holders. 2) Using derivatives like total return swaps with locked-up shareholders to gain economic exposure without physically buying the stock. Most of the index-driven buying will thus happen invisibly, not on public exchanges. For retail investors, trying to front-run these sophisticated flows is risky. More viable strategies include: waiting for post-inclusion volatility to subside before establishing a long-term position, or employing options strategies like selling strangles to profit from elevated, but potentially overstated, implied volatility around the event. In conclusion, while price appreciation may occur in the days following the announcement due to arbitrage and front-running activity, a single-day "explosive pump" on July 6th is highly unlikely. The major index fund buying will be executed efficiently and discreetly, often away from public markets, turning the anticipated climax into a well-orchestrated, anti-climactic settlement.

marsbitHá 1h

How Did Hundreds of Billions of Dollars Flow into SpaceX After Its Index Inclusion on June 26th? Will SpaceX Experience a Massive Price Surge?

marsbitHá 1h

Trading

Spot
活动图片