Crypto wallets under threat as researchers uncover new malware

来源 Cryptopolitan

Mosyle security firm has discovered a malware strain capable of bypassing antivirus software detection and stealing information from crypto browser wallets. The malware spreads via fake recruiter ads online.

Major antivirus software did not detect ModStealer malware for almost a month before reporting it. It targeted developers already working with Node.js environments. ModStealer scans for browser-based crypto wallet extensions, system credentials, and digital certificates before sending the stolen information to a command and control (C2) server. The C2 server acts as a central hub for scammers to manage compromised devices. 

ModStealer exploits Node.js to steal private keys

According to research by 9to5Mac, ModStealer malware disguised itself on macOS systems as a background helper program to achieve persistence, ensuring it ran automatically every time the computer restarted. The infected systems had a file labeled sysupdater.dat and unusual connections to suspicious servers. 

Shan Zhang, chief information security officer at SlowMist, a blockchain security company, revealed that ModStealer evades detection by mainstream antivirus software and poses a significant risk to the digital asset ecosystem. He added that the malware has multi-platform support and stealth execution, which differentiates it from traditional malware. 

Charles Guillemet, Ledger CTO, revealed another similar attack that allowed attackers to compromise a Node Package Manager (npm) developer account in an attempt to spread malicious code, which may silently replace wallet addresses during transactions. He cautioned that such incidents show how vulnerable blockchain-related code libraries can be.

“The attackers’ mistakes caused crashes in CI/CD pipelines, which led to early detection and limited impact. Still, this is a clear reminder: if your funds sit in a software wallet or on an exchange, you’re one code execution away from losing everything. Supply chain compromises remain a powerful malware delivery vector, and we’re also seeing more targeted attacks emerge.”

Charles Guillemet, Ledger CTO

Zhang warned that the ModStealer malware presents a direct threat to crypto users and platforms, adding that for individual users, the compromise of private keys, seed phrases, and exchange API keys may lead to immediate losses. He also noted that mass theft of browser extension wallet data could fuel large-scale on-chain exploits and weaken user trust while increasing risks across crypto supply chains. 

New cyber exploits target crypto wallets data

Guillemet discovered that the JavaScript ecosystem was compromised by a massive supply chain attack targeting libraries such as chalk, strip-ansi, color-convert, and error-ex. The affected packages have been downloaded more than one billion times a week, which presents a severe threat to the blockchain ecosystem. 

The malicious software worked as a crypto-clipper, meaning it could replace wallet addresses in network requests or modify transactions initiated via MetaMask and other wallets. The attack was discovered via a minor CI/CD pipeline build failure. The researchers later found that the malware used two strategies. The first strategy was passive address swapping, which monitored outgoing traffic requests and replaced wallet addresses with the hijacker’s controlled ones. It used the Levenshtein distance algorithm, which selects lookalike addresses, making it visually difficult to detect changes.

Another method the attackers utilized was active transaction hijacking, which modifies pending transactions in memory before forwarding them for user approval once a crypto wallet is detected. This tricked users into signing transfers directly to the attacker’s wallet.

Similar incidents have been reported on Cryptopolitan recently, where ReversingLabs’ research revealed another malware concealed on Ethereum smart contracts. The attack was downloaded via npm packages, including colortoolv2 and mimelib2, which acted as second-stage agents, fetching the malicious software stored on the Ethereum blockchain. 

ReversingLabs revealed that the malicious software bypassed security scans by hiding the malicious URLs within the Ethereum smart contracts. It was later downloaded through fake GitHub repositories, which posed as cryptocurrency trading bots. The operation was linked to Stargazer’s Ghost Network, a system of coordinated attacks that boost the legitimacy of malicious repositories.

If you're reading this, you’re already ahead. Stay there with our newsletter.

免责声明:仅供参考。 过去的表现并不预示未来的结果。
placeholder
Tesla股价10年大涨百倍的启示-未来特斯拉股价走势如何?特斯拉股票怎么买?经过2022年至今全球股灾的洗礼,Tesla股价拉回一段,但是自挂牌以来累计的涨幅仍然超过百倍,堪称这十年来全球新能源科技发展下的最大赢家。
作者  Mitrade
6 月 09 日 周一
经过2022年至今全球股灾的洗礼,Tesla股价拉回一段,但是自挂牌以来累计的涨幅仍然超过百倍,堪称这十年来全球新能源科技发展下的最大赢家。
placeholder
黄金、白银继续冲高,澳新银行:2025年底金价将涨至3800美元!2025年底,金价有望涨至3800美元,银价有望涨至50美元。
作者  Tony Chou
9 月 10 日 周三
2025年底,金价有望涨至3800美元,银价有望涨至50美元。
placeholder
一图看懂黄金后市,3800美元或成重要“分水岭”!随着美联储9月利率决议临近,“降息落地”或再度成为黄金多空的分水岭,鉴于投资者完全消化了9月降息预期,因而后续关键在于美联储降息进程的力度及幅度上。投资者日内可重点关注美国CPI数据,可以预见的是,一旦通胀大幅攀升发放缓美联储降息节奏,令黄金承压,但同时美国经济滞涨风险升温亦对黄金中期构成支撑。
作者  Insights
昨日 08: 01
随着美联储9月利率决议临近,“降息落地”或再度成为黄金多空的分水岭,鉴于投资者完全消化了9月降息预期,因而后续关键在于美联储降息进程的力度及幅度上。投资者日内可重点关注美国CPI数据,可以预见的是,一旦通胀大幅攀升发放缓美联储降息节奏,令黄金承压,但同时美国经济滞涨风险升温亦对黄金中期构成支撑。
placeholder
大宗商品价格飙升,澳元兑美元汇率创10个月新高!未来有望继续涨?在铁矿石、黄金价格飙升,以及美联储降息提振市场风险偏好下,澳元汇率不断上涨。
作者  Alison Ho
昨日 08: 57
在铁矿石、黄金价格飙升,以及美联储降息提振市场风险偏好下,澳元汇率不断上涨。
placeholder
9月12日财经早餐:CPI难挡FED降息,美股三大指数齐创新高!阿里巴巴涨8%创近4年新高美国上周初请失业金人数增加2.7万人至26.3万人,为近4年高位。另外,美国劳工统计局最新公布的数据显示,8月整体通胀较前月相比有所上升,但核心通胀符合预期,上述数据为美联储下周降息扫除了障碍。10年期美债收益率一度击穿4%水平至3.996%,美股三大指数齐步再创历史新高,道指历史首次站上46000点。另外,欧央行宣布维持利率于2%不变,德美利差收窄下欧元/美元重返1.1700上方,涨0.35%。国际能源署(IEA)每月报告指出,全球明年过剩供应将达每日333万桶,WTI原油重挫2.37%。
作者  Insights
12 小时前
美国上周初请失业金人数增加2.7万人至26.3万人,为近4年高位。另外,美国劳工统计局最新公布的数据显示,8月整体通胀较前月相比有所上升,但核心通胀符合预期,上述数据为美联储下周降息扫除了障碍。10年期美债收益率一度击穿4%水平至3.996%,美股三大指数齐步再创历史新高,道指历史首次站上46000点。另外,欧央行宣布维持利率于2%不变,德美利差收窄下欧元/美元重返1.1700上方,涨0.35%。国际能源署(IEA)每月报告指出,全球明年过剩供应将达每日333万桶,WTI原油重挫2.37%。
goTop
quote