Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Attackers Move Past Typosquatting to Realistic Package Impersonation

May 28, 2026

GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos

May 28, 2026

New Threat Actor Jinx-0164 Targets Crypto Developers on macOS

May 28, 2026
Facebook X (Twitter) Instagram
Thursday, May 28
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»New Threat Actor Jinx-0164 Targets Crypto Developers on macOS
News

New Threat Actor Jinx-0164 Targets Crypto Developers on macOS

Team-CWDBy Team-CWDMay 28, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A previously unreported threat actor has been observed targeting cryptocurrency firms with custom macOS malware, fake recruiter approaches and the hijacking of internal development pipelines.

Wiz has attributed the activity to a financially motivated cluster, now tracked as Jinx-0164, according to new analysis from the company.

Active since at least mid-2025 and focused almost entirely on macOS, the actor shares techniques with North Korean groups such as UNC1069, also known as Sleet. However, it implements these techniques differently and shows no infrastructure overlap with tracked actors. Wiz stopped short of linking it to any state-sponsored threat actor. 

Fake Meetings and a Cloned Audio Driver

The intrusions typically begin on LinkedIn, where the attacker poses as a business contact or recruiter using a credible profile. The target is invited to a virtual meeting on a lookalike domain impersonating a service such as Microsoft Teams.

Joining the call triggers a fake technical fault and a prompt to run a “fix,” which installs the malware. The payload, a Python-based stealer and remote access tool named Audiofix, masquerades as a system audio driver and runs on both Intel and Apple Silicon machines.

Audiofix harvests Keychain contents, browser credentials, SSH keys, cloud provider keys and details from 51 cryptocurrency wallet extensions.

It also hijacks Discord, Slack and Telegram sessions and monitors the clipboard for copied wallet addresses.

From Laptops to Code Pipelines

Rather than pivoting into cloud accounts, Jinx-0164 turned harvested GitHub tokens against the victim’s development infrastructure, using the open-source tool nord-stream to pull secrets from CI/CD pipelines.

It then injected Audiofix into internal repositories, disguising commits under other developers’ names and pushing them to main or existing branches.

When colleagues built from the poisoned repositories, their machines were infected too, turning the build process into a propagation channel. Wiz said GitHub’s Vigilant Mode, which flags unverified commits, helped expose the impersonation and halt the spread.

Read more on North Korean groups: Hackers Use Deepfake Video Calls to Target Crypto Firms

The group’s reach has extended beyond direct intrusions. On April 7, it trojanized version 4.9.1 of the npm package @velora-dex/sdk, a widely used decentralized exchange toolkit, appending code that fetched a second macOS backdoor called MINIRAT.

The recruitment-themed lure is itself well established among crypto-focused attackers, echoing earlier campaigns by groups such as Slow Pisces.

Wiz urged defenders to watch for the published indicators of compromise, unexpected use of VPN services including Mullvad, Astrill and ExpressVPN, and secret exfiltration from CI/CD workflows.

It also advised enabling logs that are off by default, such as GitHub IP logging, and treating unverified commits as suspect.

Image credit: alexgo.photography / Shutterstock.com



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleTyposquatting Is No Longer a User Problem. It’s a Supply Chain Problem
Next Article GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos
Team-CWD
  • Website

Related Posts

News

Attackers Move Past Typosquatting to Realistic Package Impersonation

May 28, 2026
News

GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos

May 28, 2026
News

Typosquatting Is No Longer a User Problem. It’s a Supply Chain Problem

May 28, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

What’s at stake if your employees post too much online

December 1, 2025

Why you should never pay to get paid

September 15, 2025

A stealthy RAT burrowing deep into Android devices

May 26, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.