Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

JPMorgan Chase, Citi and Wells Fargo Lose $5,606,000,000 to Bad Loans in Just Three Months

April 18, 2026

Crypto News: AlphaPepe Announces $870k Raised Amid Dogecoin Price Prediction Targeting $0.47 Following X Money Beta Launch

April 18, 2026

DAZN to Embed Blockchain-Backed FIFA Prediction Market in World Cup 2026 Live Streams

April 18, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Cryptojacking Campaign Targets DevOps Servers Including Nomad
Cryptojacking Campaign Targets DevOps Servers Including Nomad
Security and Privacy

Cryptojacking Campaign Targets DevOps Servers Including Nomad

July 24, 2025No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Researchers claim to have discovered the first case of threat actors using misconfigured HashiCorp Nomad deployments as an attack vector.

The popular DevOps platform, which enables firms to deploy and manage containers and non-containerized applications, is being targeted alongside other infrastructure, including Gitea, Consul and Docker API, according to cloud security provider Wiz.

The threat group in question, named by Wiz as JINX-0132, is exploiting misconfigurations and vulnerabilities in these DevOps tools for cryptojacking, the report claimed.

Based on Wiz data, a quarter (25%) of all cloud environments run at least one of the targeted technologies. Of the environments using these tools, 5% expose them directly to the internet, and among these deployments, 30% are apparently misconfigured.

Read more on cryptojacking: Malicious Microsoft VS Code Extensions Used in Cryptojacking Campaign

JINX-0132 attackers are taking advantage of Nomad’s job queue feature, which allows users to submit tasks for execution by nodes registered with the Nomad server.

“By default – and critically, if not reconfigured by administrators – any user with access to the Nomad server API can create and run these jobs. This default configuration effectively means that unrestricted access to the server API can be tantamount to remote code execution (RCE) capabilities on the server itself and all connected nodes,” Wiz said.

In this way, the threat actors create multiple new jobs on compromised hosts to download the XMRig miner directly from its public GitHub repository, unpack the archive, grant execution permissions and execute.

They are also abusing another HashiCorp tool, Consul, which is designed to help DevOps teams secure network connectivity between services and across on-premises and multi-cloud environments and runtimes.

See also  Atomic Wallet Launches $1,000,000 Bug Bounty Program Months After Suffering Multi-Million Dollar Hack

Specifically, they are hijacking the health check service to execute bash commands and download and run XMRig payloads.

“Unless ACLs [access control lists] have been configured or security features provided by HashiCorp have been enabled, any user with remote access to the server can register services and health checks and abuse this functionality for remote code execution,” Wiz warned.

JINX-0132 is also exploiting CVE-2020-14144 in older versions of open source GitHub alternative Gitea, as well as misconfigured versions of Docker Engine API. In the latter case, they have been able to create containers that launch crypto-miner images, according to the report.

Best Practices for DevOps

To avoid becoming another JINX-0132 victim, Wiz urged customers of the aforementioned DevOps tools to do the following:

  • Nomad: Implement the ACLs and other security features listed in the Security Model section of the official documentation
  • Gitea: Keep public Gitea instances up to date to prevent exploitation of RCE vulnerabilities, and don’t enable git hooks or leave the installation unlocked unless absolutely necessary
  • Consul: Switch on the security features listed in the Secure Consul section of the official documentation, including disabling script checks, and restricting the HTTP API to bind only to “localhost” where possible
  • Docker API: Do not bind the Docker API to 0.0.0.0, and don’t expose the API to the internet

Source link

campaign Cryptojacking DevOps including Nomad Servers Targets
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Cookeville Hospital Discloses Rhysida Breach Hitting 337,917

April 16, 2026

Marks & Spencer Introduces its new ‘Love That’ campaign – Inspired by the power of a simple compliment

April 16, 2026

How Lighter DEX targets RWA liquidity gap with $250K weekly incentives

April 15, 2026

Kraken is actively being extorted by criminals threatening to release the top crypto exchange’s internal data

April 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Machine Learning Algorithm Predicts 17.66% Rise In Bitcoin Price, Here’s The Target

November 20, 2023

U.S. Sen. Lummis Says ‘Delicate’ Talks Underway Over U.S. Crypto Legislation

February 4, 2024

Kraken NFT Marketplace Launches, Supports 250 NFT Collections

June 8, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

JPMorgan Chase, Citi and Wells Fargo Lose $5,606,000,000 to Bad Loans in Just Three Months

April 18, 2026

Crypto News: AlphaPepe Announces $870k Raised Amid Dogecoin Price Prediction Targeting $0.47 Following X Money Beta Launch

April 18, 2026

DAZN to Embed Blockchain-Backed FIFA Prediction Market in World Cup 2026 Live Streams

April 18, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$76,672.001.87%
  • ethereumEthereum(ETH)$2,383.341.45%
  • tetherTether(USDT)$1.000.01%
  • rippleXRP(XRP)$1.450.80%
  • binancecoinBNB(BNB)$637.531.23%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$87.60-1.16%
  • tronTRON(TRX)$0.3275970.92%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.02-1.20%
  • dogecoinDogecoin(DOGE)$0.097566-0.84%