Crypto2Community
HomeCrypto NewsReviewsGuidesGamblingTradingPress Release

Crypto 2 Community

  • About Us
  • Editorial Policy
  • Why Trust Us
  • Contact Us
  • Privacy Policy
  • Submit a Press Release

Cryptocurrency

  • Best Cryptos to Buy Now
  • Best Crypto Exchanges
  • How To Buy Cryptocurrency
  • Best Crypto Wallets
  • Best Altcoins to Buy

Gambling

  • Best Bitcoin Casinos
  • Best Ethereum Casinos
  • Best Crypto Live Casinos
  • Best Crypto Faucet Casinos
  • Provably Fair Bitcoin Casinos

Best Platforms

  • eToro Review
  • BC.Game Review
  • Jackbit Review
  • Metaspins Review
  • CryptoLeo Review

© 2026 Crypto2Community.com

CAUTION: The content presented on this platform is not intended as financial guidance, and we lack the authorization to offer investment advice. Any material found on this website should not be construed as an endorsement or recommendation of any specific trading strategy or investment decision. The information provided herein is of a general nature, and therefore it is essential to evaluate it in the context of your objectives, financial circumstances, and requirements.

Investment activities involve speculation and entail inherent risks to your capital. This website is not intended for utilization in jurisdictions where the described trading or investment activities are prohibited, and it should only be accessed by individuals who are legally permitted to do so. Depending on your country or state of residence, your investment may not be eligible for investor protection, hence it is advisable to conduct thorough research independently or seek appropriate guidance. While this website is accessible to you free of charge, please note that we may receive commissions from the companies featured on this site.

Disclosure: 18+ Rules regarding online gambling vary from country to country, please ensure you are following them and gamble responsibly. The content on this website is provided for entertainment purposes only. We may utilise affiliate links within our content, and receive commission.

Home/Crypto News
Crypto News

Researchers Uncover New Malware Targeting Crypto Wallets Across Windows, Mac, and Linux

Author
Syed Ali Haider
Syed Ali Haider
Crypto Writer
Fact Checked by Joshua Downes
Last updated: September 12, 2025
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.
TweetShareLinkedIn0
Researchers Uncover New Malware Targeting Crypto Wallets Across Windows, Mac, and Linux

Highlights:

  • ModStealer malware targets crypto wallets across Windows, macOS, and Linux systems undetected.
  • Attackers spread ModStealer via fake job ads, exploiting Node.js developer environments.
  • Experts warn ModStealer poses a major risk to digital assets and wallet security.

Cybersecurity researchers have identified a new infostealer malware designed to target cryptocurrency wallets. The malware can extract private keys and other sensitive information from Windows, Linux, and macOS systems while remaining undetected by major antivirus engines. Mosyle, a security platform specializing in Apple device management, discovered the malware, known as ModStealer, after it evaded detection for several weeks across major antivirus programs.

Advertisement

Banner

Researchers uncovered ModStealer, a cross-platform malware that drains crypto from browser wallets.

• It spreads via fake recruiter ads and hides as a background helper.
• Targets wallet extensions, credentials and seed phrases.
• Runs on Windows, Linux, and macOS.

A single… pic.twitter.com/XFelomyumM

— Web3 Antivirus (@web3_antivirus) September 12, 2025

Malware Evades Detection Across Systems

According to Mosyle, the malware remained invisible to all major antivirus engines since first appearing on VirusTotal nearly a month ago. Although the company primarily focuses on Mac-based security threats, it warned that ModStealer is capable of infiltrating Windows and Linux-powered systems as well.

There are also indications that ModStealer might have been offered as Malware-as-a-Service. This model allows cybercriminals with limited technical skills to deploy it across multiple platforms using pre-made malicious code. Malware-as-a-Service is an underground business approach in which malicious developers sell or lease malware kits to affiliates. Affiliates typically pay a commission or subscription fee in exchange for access to these ready-to-use malware tools.

ModStealer Malware Threat and How It Spreads

Mosyle’s analysis found that attackers were spreading ModStealer through fake job recruiter ads, mainly targeting developers. The malware is hard to detect because it uses a heavily obfuscated JavaScript file within a Node.js environment.

Developers frequently handle sensitive credentials, access keys, and crypto wallets, which makes them valuable targets for cybercriminals. Node.js environments are commonly used by developers and often have elevated permissions during testing and deployment. This makes them appealing entry points for attackers.

As an infostealer, ModStealer’s primary goal is to exfiltrate data once it reaches a victim’s system. The malware comes preloaded with code that targets at least 56 different browser wallet extensions, including Safari, to steal crypto private keys. It can retrieve clipboard data, capture screens, and remotely execute malicious code. Mosyle warned that this gives attackers nearly complete control over infected devices. 

“What makes this discovery so alarming is the stealth with which ModStealer operates. Undetectable malware is a huge problem for signature-based detection since it can quietly go unnoticed without being flagged,” it added. On macOS, ModStealer can integrate with the system’s launchctl tool, a built-in utility that manages background processes. This allows the malware to appear as a legitimate service and automatically run whenever the device starts. Mosyle also found that data taken from victims is sent to a server in Finland, linked to Germany, probably to hide the attackers’ location.

Industry Experts Warn of Serious Risks

Shan Zhang, chief information security officer at SlowMist, a blockchain security company, revealed that ModStealer bypasses mainstream antivirus software and poses a major risk to the digital asset ecosystem. He added that its multi-platform support and stealth execution set it apart from traditional malware. Charles Guillemet, Ledger CTO, disclosed a similar attack targeting a Node Package Manager (npm) developer account to spread malicious code. He warned that such attacks can silently replace wallet addresses during transactions.

Update on the NPM attack: The attack fortunately failed, with almost no victims.🔒

It began with a phishing email from a fake npm support domain that stole credentials and gave attackers access to publish malicious package updates. The injected code targeted web crypto activity,… https://t.co/Ud1SBSJ52v pic.twitter.com/lOik6k7Dkp

— Charles Guillemet (@P3b7_) September 9, 2025

eToro Platform

Best Crypto Exchange

  • Over 90 top cryptos to trade
  • Regulated by top-tier entities
  • User-friendly trading app
  • 30+ million users
9.9

5 Stars

Visit eToro

eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.

Advertisement

Banner

Tags

Crypto WalletDeFiModStealer MalwareMosyle
Syed Ali Haider
Author

Syed Ali Haider

Ali Haider is a contributing crypto writer at Crypto2Community. He is a crypto and blockchain journalist with over six years of experience and has long advocated for digital freedom and cybersecurity. Haider has been featured in several high-profile crypto and finance outlets, including Coincult, AltcoinBeacon, BTCRead, and more.

View full profile ›

ℹ️About Crypto2Community's Editorial Process

Crypto2Community's editorial policy is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict editorial policy and sourcing standards, and each page undergoes diligent review by our team of top crypto industry experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

More by this author:

  • XRP Network Activity Hits Two-Month High After Price Rebound
  • Best Memecoins to Watch Today, May 16 – PENGU, SHIB, PEPE
  • Italy’s Largest Bank Raises Crypto Exposure to $235 Million Through Bitcoin and Altcoin ETFs

Related Articles:

XRP Network Activity Hits Two-Month High After Price Rebound
XRP Network Activity Hits Two-Month High After Price Rebound
Crypto News10 hours ago
Raymond Munene
By Raymond Munene5/16/2026
Best Memecoins to Watch Today, May 16 – PENGU, SHIB, PEPE
Best Memecoins to Watch Today, May 16 – PENGU, SHIB, PEPE
Crypto News13 hours ago
Austin Mwendia
By Austin Mwendia5/16/2026
Italy’s Largest Bank Raises Crypto Exposure to $235 Million Through Bitcoin and Altcoin ETFs
Italy’s Largest Bank Raises Crypto Exposure to $235 Million Through Bitcoin and Altcoin ETFs
Crypto News13 hours ago
Syed Ali Haider
By Syed Ali Haider5/16/2026

Advertisement

Banner

Advertisement

Banner

🔥Latest offers

Play Now

9.85 Stars

🔥 Get up to 60% with all rewards

Claim Bonus

9.65 Stars

💸 300% deposit bonus up to 20,000 USD

Visit eToro

9.95 Stars

Best Crypto Exchange 2025

Virtual currencies are highly volatile. Your capital is at risk.

Visit KuCoin

9.55 Stars

Trading features & low fees

Popular Topics

  • Sei Price Prediction 2025, 2030, 2040
  • Uniswap Price Prediction 2025, 2030, 2040
  • Near Protocol Price Prediction 2025, 2030, 2040
  • Loopring Price Prediction 2025, 2030, 2040
  • Chainlink Price Prediction 2025, 2030, 2040

Trending News

  • XRP Network Activity Hits Two-Month High After Price Rebound
  • Best Memecoins to Watch Today, May 16 – PENGU, SHIB, PEPE
  • Italy’s Largest Bank Raises Crypto Exposure to $235 Million Through Bitcoin and Altcoin ETFs
  • THORChain Opens Recovery Portal After $10 Million Cross-Chain Hack
  • Bitcoin and Ethereum ETFs See Heavy Outflows as Crypto Fund Demand Cools
  • Bitcoin Social Euphoria Spikes After CLARITY Act Clears Senate Committee
  • Strategy Plans $1.5B Note Buyback While Leaving Door Open to Bitcoin Sales
  • Poland’s Crypto Bill Advances Amid $95.9M Zondacrypto Loss Claims
  • Myanmar Proposes Death Penalty for Severe Online Scam Crimes
  • Hyperliquid Price Prediction – Bitwise’s BHYP ETF Could Push HYPE Through $50 Soon
  • Bitcoin Price Analysis – Bullish Rebound Above $80K Signals Potential Rally Toward $89K
  • Bitwise Launches Hyperliquid ETF on NYSE with HYPE Staking Rewards
  • Top Crypto Picks Today, May 15 – Solana, Hyperliquid, Cardano
  • Crypto Industry Cheers as CLARITY Act Clears Senate Banking Committee
  • Bitcoin Price Must Reclaim $88K to Avoid Drop Toward $70K, CryptoQuant Says
  • CLARITY Act Advances as Senate Panel Sends Crypto Bill to Floor
  • Bitcoin Price Forecast – Bears Target $75K Amid Rising Liquidations and ETF Outflows
  • Solana Price Analysis – SOL Could Fall to $82 If $90 Support Breaks
  • Best Crypto Gainers Today, May 14 – Kite, Humanity, Canton
  • David Schwartz Warns XRPL Users After Surge in Wallet Drainer Scams