A newly uncovered malware strain dubbed ModStealer is targeting cryptocurrency users across macOS, Windows and Linux, according to security researchers.
Apple-focused firm Mosyle revealed the malware, noting it went undetected by major antivirus tools for nearly a month after being uploaded to VirusTotal. ModStealer is designed to steal private keys, browser-based wallet extensions, certificates and credentials, persisting on macOS by registering as a background agent. Researchers believe its infrastructure is routed through Germany to conceal the operators’ origins.
The malware is being spread through fake job ads — a tactic increasingly used to target Web3 developers. Once installed, it...