Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

New Threat Actor Jinx-0164 Targets Crypto Developers on macOS

May 28, 2026

South Korea arrests criminal group in first DEX rug pull case

May 28, 2026

Sui blockchain suffers another network outage as transactions grind to a halt

May 28, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»New Threat Actor Jinx-0164 Targets Crypto Developers on macOS
New Threat Actor Jinx-0164 Targets Crypto Developers on macOS
Security

New Threat Actor Jinx-0164 Targets Crypto Developers on macOS

May 28, 2026No Comments3 Mins Read

A previously unreported threat actor has been observed targeting cryptocurrency firms with custom macOS malware, fake recruiter approaches and the hijacking of internal development pipelines.

Wiz has attributed the activity to a financially motivated cluster, now tracked as Jinx-0164, according to new analysis from the company.

Active since at least mid-2025 and focused almost entirely on macOS, the actor shares techniques with North Korean groups such as UNC1069, also known as Sleet. However, it implements these techniques differently and shows no infrastructure overlap with tracked actors. Wiz stopped short of linking it to any state-sponsored threat actor. 

Fake Meetings and a Cloned Audio Driver

The intrusions typically begin on LinkedIn, where the attacker poses as a business contact or recruiter using a credible profile. The target is invited to a virtual meeting on a lookalike domain impersonating a service such as Microsoft Teams.

Joining the call triggers a fake technical fault and a prompt to run a “fix,” which installs the malware. The payload, a Python-based stealer and remote access tool named Audiofix, masquerades as a system audio driver and runs on both Intel and Apple Silicon machines.

Audiofix harvests Keychain contents, browser credentials, SSH keys, cloud provider keys and details from 51 cryptocurrency wallet extensions.

It also hijacks Discord, Slack and Telegram sessions and monitors the clipboard for copied wallet addresses.

From Laptops to Code Pipelines

Rather than pivoting into cloud accounts, Jinx-0164 turned harvested GitHub tokens against the victim’s development infrastructure, using the open-source tool nord-stream to pull secrets from CI/CD pipelines.

It then injected Audiofix into internal repositories, disguising commits under other developers’ names and pushing them to main or existing branches.

See also  North Korea's Crypto Hack Playbook Won't Work on Canton Network, Says Digital Asset CEO

When colleagues built from the poisoned repositories, their machines were infected too, turning the build process into a propagation channel. Wiz said GitHub’s Vigilant Mode, which flags unverified commits, helped expose the impersonation and halt the spread.

Read more on North Korean groups: Hackers Use Deepfake Video Calls to Target Crypto Firms

The group’s reach has extended beyond direct intrusions. On April 7, it trojanized version 4.9.1 of the npm package @velora-dex/sdk, a widely used decentralized exchange toolkit, appending code that fetched a second macOS backdoor called MINIRAT.

The recruitment-themed lure is itself well established among crypto-focused attackers, echoing earlier campaigns by groups such as Slow Pisces.

Wiz urged defenders to watch for the published indicators of compromise, unexpected use of VPN services including Mullvad, Astrill and ExpressVPN, and secret exfiltration from CI/CD workflows.

It also advised enabling logs that are off by default, such as GitHub IP logging, and treating unverified commits as suspect.

Image credit: alexgo.photography / Shutterstock.com

Source link

Actor Crypto Developers Jinx0164 macOS Targets Threat

Related Posts

South Korea arrests criminal group in first DEX rug pull case

May 28, 2026

Top Crypto Prop Firms List: Reviews and Comparisons

May 28, 2026

DeFi isn’t safe anymore because AI is becoming ‘superhuman’ at hacking, security chief warns

May 28, 2026

WhatsApp ‘star traders’ script fake wins for Australia’s Gen Z

May 28, 2026
Top Posts

General Bytes Bitcoin ATMs Hacked to Steal Funds

October 6, 2023

MARA launches foundation to fund Bitcoin research, education, and open source work

April 28, 2026

El Salvador pro-Bitcoin president Nayib Bukele launches re-election bid

October 30, 2023

Type above and press Enter to search. Press Esc to cancel.