• bitcoinBitcoin (BTC) $ 113,060.00
  • ethereumEthereum (ETH) $ 3,990.02
  • tetherTether (USDT) $ 1.00
  • xrpXRP (XRP) $ 2.61
  • bnbBNB (BNB) $ 1,104.11
  • usd-coinUSDC (USDC) $ 0.999846
  • staked-etherLido Staked Ether (STETH) $ 3,987.24
  • dogecoinDogecoin (DOGE) $ 0.193614
  • tronTRON (TRX) $ 0.295367
  • cardanoCardano (ADA) $ 0.646485
  • wrapped-stethWrapped stETH (WSTETH) $ 4,855.36
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 112,964.00
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,308.81
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • hyperliquidHyperliquid (HYPE) $ 47.72
  • chainlinkChainlink (LINK) $ 17.84
  • bitcoin-cashBitcoin Cash (BCH) $ 557.78
  • wrapped-eethWrapped eETH (WEETH) $ 4,302.28
  • stellarStellar (XLM) $ 0.318683
  • ethena-usdeEthena USDe (USDE) $ 0.999667
  • usdsUSDS (USDS) $ 1.00
  • suiSui (SUI) $ 2.51
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • leo-tokenLEO Token (LEO) $ 9.57
  • wethWETH (WETH) $ 3,985.01
  • avalanche-2Avalanche (AVAX) $ 19.51
  • hedera-hashgraphHedera (HBAR) $ 0.194764
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 112,984.00
  • litecoinLitecoin (LTC) $ 97.04
  • usdt0USDT0 (USDT0) $ 1.00
  • moneroMonero (XMR) $ 335.91
  • whitebitWhiteBIT Coin (WBT) $ 42.49
  • shiba-inuShiba Inu (SHIB) $ 0.000010
  • the-open-networkToncoin (TON) $ 2.23
  • crypto-com-chainCronos (CRO) $ 0.150760
  • mantleMantle (MNT) $ 1.61
  • zcashZcash (ZEC) $ 314.85
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • daiDai (DAI) $ 1.00
  • polkadotPolkadot (DOT) $ 3.05
  • bittensorBittensor (TAO) $ 433.26
  • memecoreMemeCore (M) $ 2.27
  • uniswapUniswap (UNI) $ 6.35
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.138040
  • aaveAave (AAVE) $ 228.90
  • susdssUSDS (SUSDS) $ 1.07
  • okbOKB (OKB) $ 163.08
  • ethenaEthena (ENA) $ 0.461948
  • bitget-tokenBitget Token (BGB) $ 4.70
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • pepePepe (PEPE) $ 0.000007
  • nearNEAR Protocol (NEAR) $ 2.24
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • paypal-usdPayPal USD (PYUSD) $ 0.999915
  • jito-staked-solJito Staked SOL (JITOSOL) $ 240.69
  • solanaSolana (SOL) $ 194.13
  • ethereum-classicEthereum Classic (ETC) $ 15.93
  • aptosAptos (APT) $ 3.36
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,985.07
  • ondo-financeOndo (ONDO) $ 0.729618
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 5.53
  • aster-2Aster (ASTER) $ 1.07
  • falcon-financeFalcon USD (USDF) $ 0.998066
  • pi-networkPi Network (PI) $ 0.253036
  • tether-goldTether Gold (XAUT) $ 3,956.17
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.194682
  • worldcoin-wldWorldcoin (WLD) $ 0.870085
  • usdtbUSDtb (USDTB) $ 0.999100
  • rocket-pool-ethRocket Pool ETH (RETH) $ 4,571.59
  • gatechain-tokenGate (GT) $ 14.95
  • arbitrumArbitrum (ARB) $ 0.315110
  • htx-daoHTX DAO (HTX) $ 0.000002
  • kucoin-sharesKuCoin (KCS) $ 13.31
  • binance-staked-solBinance Staked SOL (BNSOL) $ 209.76
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 47.89
  • internet-computerInternet Computer (ICP) $ 3.08
  • pump-funPump.fun (PUMP) $ 0.004628
  • hash-2Provenance Blockchain (HASH) $ 0.032405
  • algorandAlgorand (ALGO) $ 0.184895
  • story-2Story (IP) $ 5.04
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 4,211.94
  • kaspaKaspa (KAS) $ 0.056584
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 4,210.35
  • cosmosCosmos Hub (ATOM) $ 3.10
  • vechainVeChain (VET) $ 0.016778
  • official-trumpOfficial Trump (TRUMP) $ 7.20
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 4,291.75
  • wbnbWrapped BNB (WBNB) $ 1,103.82
  • skySky (SKY) $ 0.058323
  • jupiter-exchange-solanaJupiter (JUP) $ 0.429641
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 112,819.00
  • syrupusdcSyrup USDC (SYRUPUSDC) $ 1.13
  • bfusdBFUSD (BFUSD) $ 1.00
  • pax-goldPAX Gold (PAXG) $ 3,954.66
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.020635
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.10
  • flare-networksFlare (FLR) $ 0.016601
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 4,231.94
  • render-tokenRender (RENDER) $ 2.43
  • sei-networkSei (SEI) $ 0.195653
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 1.00
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 112,528.00
  • nexoNEXO (NEXO) $ 1.13
  • bonkBonk (BONK) $ 0.000014
  • filecoinFilecoin (FIL) $ 1.56
  • xdce-crowd-saleXDC Network (XDC) $ 0.060726
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997291
  • morphoMorpho (MORPHO) $ 1.93
  • immutable-xImmutable (IMX) $ 0.519490
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 1.51
  • mantle-staked-etherMantle Staked Ether (METH) $ 4,300.69
  • global-dollarGlobal Dollar (USDG) $ 0.999913
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 222.51
  • spx6900SPX6900 (SPX) $ 1.02
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 112,876.00
  • ripple-usdRipple USD (RLUSD) $ 0.999705
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.61
  • clbtcclBTC (CLBTC) $ 112,763.00
  • aerodrome-financeAerodrome Finance (AERO) $ 0.969902
  • celestiaCelestia (TIA) $ 1.01
  • fasttokenFasttoken (FTN) $ 2.01
  • optimismOptimism (OP) $ 0.435626
  • injective-protocolInjective (INJ) $ 8.39
  • hashnote-usycCircle USYC (USYC) $ 1.10
  • lido-daoLido DAO (LDO) $ 0.903806
  • doublezeroDoubleZero (2Z) $ 0.231804
  • msolMarinade Staked SOL (MSOL) $ 259.11
  • blockstackStacks (STX) $ 0.442864
  • chainopera-aiChainOpera AI (COAI) $ 4.09
  • ousgOUSG (OUSG) $ 113.09
  • curve-dao-tokenCurve DAO (CRV) $ 0.531078
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.87
  • plasmaPlasma (XPL) $ 0.372964
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 4,225.31
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,985.79
  • flokiFLOKI (FLOKI) $ 0.000071
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.10
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.998543
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.257462
  • tbtctBTC (TBTC) $ 112,364.00
  • the-graphThe Graph (GRT) $ 0.062499
  • pyth-networkPyth Network (PYTH) $ 0.111792
  • kaiaKaia (KAIA) $ 0.108284
  • tezosTezos (XTZ) $ 0.591525
  • sonic-3Sonic (S) $ 0.161459
  • stader-ethxStader ETHx (ETHX) $ 4,275.74
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,985.18
  • gtethGTETH (GTETH) $ 3,988.15
  • iotaIOTA (IOTA) $ 0.143998
  • usdaiUSDai (USDAI) $ 1.01
  • beldexBeldex (BDX) $ 0.078207
  • dashDash (DASH) $ 45.83
  • conflux-tokenConflux (CFX) $ 0.111053
  • humanityHumanity (H) $ 0.309363
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999902
  • newton-projectAB (AB) $ 0.006625
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999841
  • usual-usdUsual USD (USD0) $ 0.998043
  • pendlePendle (PENDLE) $ 3.23
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 4,385.33
  • ether-fiEther.fi (ETHFI) $ 0.951335
  • dogwifcoindogwifhat (WIF) $ 0.534569
  • swethSwell Ethereum (SWETH) $ 4,400.45
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 112,932.00
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.25
  • theta-tokenTheta Network (THETA) $ 0.518870
  • ethereum-name-serviceEthereum Name Service (ENS) $ 15.51
  • the-sandboxThe Sandbox (SAND) $ 0.210034
  • starknetStarknet (STRK) $ 0.118868
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 1.00
  • ape-and-pepeApe and Pepe (APEPE) $ 0.000002
  • wrapped-hypeWrapped HYPE (WHYPE) $ 47.58
  • galaGALA (GALA) $ 0.010782
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.193465
  • true-usdTrueUSD (TUSD) $ 0.998237
  • jasmycoinJasmyCoin (JASMY) $ 0.010179
  • myx-financeMYX Finance (MYX) $ 2.57
  • bittorrentBitTorrent (BTT) $ 0.00000050
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,980.24
  • raydiumRaydium (RAY) $ 1.80
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.11
  • astherus-staked-bnbAster Staked BNB (ASBNB) $ 1,167.03
  • arbitrum-bridged-wrapped-eethArbitrum Bridged Wrapped eETH (Arbitrum) (WEETH) $ 4,296.86
  • vaultaVaulta (A) $ 0.284700
  • benqi-liquid-staked-avaxBENQI Liquid Staked AVAX (SAVAX) $ 24.01
  • swissborgSwissBorg (BORG) $ 0.462623
  • decentralandDecentraland (MANA) $ 0.236139
  • heliumHelium (HNT) $ 2.43
  • bitcoin-svBitcoin SV (BSV) $ 22.49
  • usddUSDD (USDD) $ 0.999916
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 4,299.08
  • kinetiq-earn-vaultKinetiq Earn Vault (VKHYPE) $ 48.14
  • flowFlow (FLOW) $ 0.269339
  • sun-tokenSun Token (SUN) $ 0.022690
  • syrupMaple Finance (SYRUP) $ 0.388773
  • polygon-pos-bridged-weth-polygon-posPolygon PoS Bridged WETH (Polygon POS) (WETH) $ 3,982.64
  • ghoGHO (GHO) $ 0.999773
  • satoshi-stablecoinSatoshi Stablecoin (SATUSD) $ 0.994404
  • jito-governance-tokenJito (JTO) $ 1.06
  • aethirAethir (ATH) $ 0.029003

Researchers Uncover Undetectable Malware Draining Crypto Browser Wallets

0 23

Researchers Uncover Undetectable Malware Draining Crypto Browser Wallets

A new malware strain that can slip past antivirus checks and steal data from crypto wallets on Windows, Linux, and macOS systems was discovered on Thursday.

Dubbed ModStealer, it had remained undetected by major antivirus engines for almost a month at the time of disclosure, with its package being delivered through fake job recruiter ads targeting developers. 

The disclosure was made by security firm Mosyle, according to an initial report from 9to5Mac. Decrypt has reached out to Mosyle to learn more.



Distributing through fake job recruiter ads was an intentional tactic, according to Mosyle, because it was designed to reach developers who were likely already using or had Node.js environments installed.

ModStealer “evades detection by mainstream antivirus solutions and poses significant risks to the broader digital asset ecosystem,” Shān Zhang, chief information security officer at blockchain security firm Slowmist, told Decrypt. “Unlike traditional stealers, ModStealer stands out for its multi-platform support and stealthy ‘zero-detection’ execution chain.”

Once executed, the malware scans for browser-based crypto wallet extensions, system credentials, and digital certificates. 

It then “exfiltrates the data to remote C2 servers,” Zhang explained. A C2, or “Command and Control” server, is a centralized system used by cybercriminals to manage and control compromised devices in a network, acting as the operational hub for malware and cyberattacks.

On Apple hardware running macOS, the malware sets itself up through a “persistence method” to run automatically every time the computer starts by disguising itself as a background helper program. 

The setup keeps it running quietly without the user noticing. Signs of infection include a secret file called “.sysupdater.dat” and connections to a suspicious server, per the disclosure.

“Although common in isolation, these persistence methods combined with strong obfuscation make ModStealer resilient against signature-based security tools,” Zhang said.

The discovery of ModStealer comes on the heels of a related warning from Ledger CTO Charles Guillemet, who disclosed Tuesday that attackers had compromised an NPM developer account and attempted to spread malicious code that could silently replace crypto wallet addresses during transactions, putting funds at risk across multiple blockchains.

Although the attack was detected early and failed, Guillemet later noted that the compromised packages had been hooked to Ethereum, Solana, and other chains.

“If your funds sit in a software wallet or on an exchange, you’re one code execution away from losing everything.” Guillemet tweeted hours after his initial warning.

Asked about the new malware’s possible impact, Zhang warned that ModStealer poses a “direct threat to crypto users and platforms.”

For end-users, “private keys, seed phrases, and exchange API keys may be compromised, resulting in direct asset loss,” Zhang said, adding that for the crypto industry, “mass theft of browser extension wallet data could trigger large-scale on-chain exploits, eroding trust and amplifying supply chain risks.”

Source

Leave A Reply

Your email address will not be published.