Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Alcoa Nears Sale of New York Smelter Site to NYDIG: Bloomberg

April 17, 2026

Why JPMorgan says the U.S. crypto rulebook is ‘close to completion’

April 17, 2026

Flare Proposes MEV Capture and 40% Inflation Cut Ahead of Vote

April 17, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Cryptojacking Campaign Targets DevOps Servers Including Nomad
Cryptojacking Campaign Targets DevOps Servers Including Nomad
Security and Privacy

Cryptojacking Campaign Targets DevOps Servers Including Nomad

July 24, 2025No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Researchers claim to have discovered the first case of threat actors using misconfigured HashiCorp Nomad deployments as an attack vector.

The popular DevOps platform, which enables firms to deploy and manage containers and non-containerized applications, is being targeted alongside other infrastructure, including Gitea, Consul and Docker API, according to cloud security provider Wiz.

The threat group in question, named by Wiz as JINX-0132, is exploiting misconfigurations and vulnerabilities in these DevOps tools for cryptojacking, the report claimed.

Based on Wiz data, a quarter (25%) of all cloud environments run at least one of the targeted technologies. Of the environments using these tools, 5% expose them directly to the internet, and among these deployments, 30% are apparently misconfigured.

Read more on cryptojacking: Malicious Microsoft VS Code Extensions Used in Cryptojacking Campaign

JINX-0132 attackers are taking advantage of Nomad’s job queue feature, which allows users to submit tasks for execution by nodes registered with the Nomad server.

“By default – and critically, if not reconfigured by administrators – any user with access to the Nomad server API can create and run these jobs. This default configuration effectively means that unrestricted access to the server API can be tantamount to remote code execution (RCE) capabilities on the server itself and all connected nodes,” Wiz said.

In this way, the threat actors create multiple new jobs on compromised hosts to download the XMRig miner directly from its public GitHub repository, unpack the archive, grant execution permissions and execute.

They are also abusing another HashiCorp tool, Consul, which is designed to help DevOps teams secure network connectivity between services and across on-premises and multi-cloud environments and runtimes.

See also  New macOS Malware Targets Cracked Apps

Specifically, they are hijacking the health check service to execute bash commands and download and run XMRig payloads.

“Unless ACLs [access control lists] have been configured or security features provided by HashiCorp have been enabled, any user with remote access to the server can register services and health checks and abuse this functionality for remote code execution,” Wiz warned.

JINX-0132 is also exploiting CVE-2020-14144 in older versions of open source GitHub alternative Gitea, as well as misconfigured versions of Docker Engine API. In the latter case, they have been able to create containers that launch crypto-miner images, according to the report.

Best Practices for DevOps

To avoid becoming another JINX-0132 victim, Wiz urged customers of the aforementioned DevOps tools to do the following:

  • Nomad: Implement the ACLs and other security features listed in the Security Model section of the official documentation
  • Gitea: Keep public Gitea instances up to date to prevent exploitation of RCE vulnerabilities, and don’t enable git hooks or leave the installation unlocked unless absolutely necessary
  • Consul: Switch on the security features listed in the Secure Consul section of the official documentation, including disabling script checks, and restricting the HTTP API to bind only to “localhost” where possible
  • Docker API: Do not bind the Docker API to 0.0.0.0, and don’t expose the API to the internet

Source link

campaign Cryptojacking DevOps including Nomad Servers Targets
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Cookeville Hospital Discloses Rhysida Breach Hitting 337,917

April 16, 2026

Marks & Spencer Introduces its new ‘Love That’ campaign – Inspired by the power of a simple compliment

April 16, 2026

How Lighter DEX targets RWA liquidity gap with $250K weekly incentives

April 15, 2026

Kraken is actively being extorted by criminals threatening to release the top crypto exchange’s internal data

April 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Web3’s First Handheld Gaming Device

April 12, 2024

Blockchain Association Files Another Amicus Brief Supporting Tornado Cash, Says Crypto Mixer Is ‘Simply a Tool’

June 3, 2023

Story [IP] surges 27% as volume explodes 100%, but THIS raises risks

April 17, 2026

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Alcoa Nears Sale of New York Smelter Site to NYDIG: Bloomberg

April 17, 2026

Why JPMorgan says the U.S. crypto rulebook is ‘close to completion’

April 17, 2026

Flare Proposes MEV Capture and 40% Inflation Cut Ahead of Vote

April 17, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$77,131.002.85%
  • ethereumEthereum(ETH)$2,419.883.25%
  • tetherTether(USDT)$1.000.01%
  • rippleXRP(XRP)$1.481.97%
  • binancecoinBNB(BNB)$643.801.34%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$88.890.12%
  • tronTRON(TRX)$0.3280890.39%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.02-0.17%
  • dogecoinDogecoin(DOGE)$0.0993260.47%