Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Worldcoin at risk? WLD plunges 16% – But THIS level still matters

May 28, 2026

Will Most Anti-Crypto Congressman Lose His Seat?

May 28, 2026

New Threat Actor Jinx-0164 Targets Crypto Developers on macOS

May 28, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»New Threat Actor Jinx-0164 Targets Crypto Developers on macOS
New Threat Actor Jinx-0164 Targets Crypto Developers on macOS
Security and Privacy

New Threat Actor Jinx-0164 Targets Crypto Developers on macOS

May 28, 2026No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A previously unreported threat actor has been observed targeting cryptocurrency firms with custom macOS malware, fake recruiter approaches and the hijacking of internal development pipelines.

Wiz has attributed the activity to a financially motivated cluster, now tracked as Jinx-0164, according to new analysis from the company.

Active since at least mid-2025 and focused almost entirely on macOS, the actor shares techniques with North Korean groups such as UNC1069, also known as Sleet. However, it implements these techniques differently and shows no infrastructure overlap with tracked actors. Wiz stopped short of linking it to any state-sponsored threat actor. 

Fake Meetings and a Cloned Audio Driver

The intrusions typically begin on LinkedIn, where the attacker poses as a business contact or recruiter using a credible profile. The target is invited to a virtual meeting on a lookalike domain impersonating a service such as Microsoft Teams.

Joining the call triggers a fake technical fault and a prompt to run a “fix,” which installs the malware. The payload, a Python-based stealer and remote access tool named Audiofix, masquerades as a system audio driver and runs on both Intel and Apple Silicon machines.

Audiofix harvests Keychain contents, browser credentials, SSH keys, cloud provider keys and details from 51 cryptocurrency wallet extensions.

It also hijacks Discord, Slack and Telegram sessions and monitors the clipboard for copied wallet addresses.

From Laptops to Code Pipelines

Rather than pivoting into cloud accounts, Jinx-0164 turned harvested GitHub tokens against the victim’s development infrastructure, using the open-source tool nord-stream to pull secrets from CI/CD pipelines.

It then injected Audiofix into internal repositories, disguising commits under other developers’ names and pushing them to main or existing branches.

See also  Ripple CLO Says SEC's Crypto Security War is "Political Power Play"

When colleagues built from the poisoned repositories, their machines were infected too, turning the build process into a propagation channel. Wiz said GitHub’s Vigilant Mode, which flags unverified commits, helped expose the impersonation and halt the spread.

Read more on North Korean groups: Hackers Use Deepfake Video Calls to Target Crypto Firms

The group’s reach has extended beyond direct intrusions. On April 7, it trojanized version 4.9.1 of the npm package @velora-dex/sdk, a widely used decentralized exchange toolkit, appending code that fetched a second macOS backdoor called MINIRAT.

The recruitment-themed lure is itself well established among crypto-focused attackers, echoing earlier campaigns by groups such as Slow Pisces.

Wiz urged defenders to watch for the published indicators of compromise, unexpected use of VPN services including Mullvad, Astrill and ExpressVPN, and secret exfiltration from CI/CD workflows.

It also advised enabling logs that are off by default, such as GitHub IP logging, and treating unverified commits as suspect.

Image credit: alexgo.photography / Shutterstock.com

Source link

actor Crypto Developers Jinx0164 macOS Targets threat
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Top Crypto Prop Firms List: Reviews and Comparisons

May 28, 2026

Crypto Advocacy Group Urges Senate Yes Vote After CLARITY Act Advances

May 28, 2026

South Korea Sets National Goal for Digital Asset Ecosystem, Targets February 2027 for Security Token Act

May 28, 2026

Russia set to ban crypto mining in Moscow, prosecute illegal miners

May 28, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Polyhedra Network Unveils Groundbreaking ZK Proof Method for Bitcoin Blockchain

March 24, 2024

47 countries pledge to authorize the crypto-asset reporting framework by 2027

November 12, 2023

RBI Deputy Governor’s Reappointment Could Maintain Crypto Policy Status Quo

January 15, 2024

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Worldcoin at risk? WLD plunges 16% – But THIS level still matters

May 28, 2026

Will Most Anti-Crypto Congressman Lose His Seat?

May 28, 2026

New Threat Actor Jinx-0164 Targets Crypto Developers on macOS

May 28, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$73,105.00-2.50%
  • ethereumEthereum(ETH)$1,996.41-3.18%
  • tetherTether(USDT)$1.00-0.01%
  • binancecoinBNB(BNB)$636.37-2.91%
  • rippleXRP(XRP)$1.31-1.20%
  • usd-coinUSDC(USDC)$1.00-0.01%
  • solanaSolana(SOL)$81.38-3.15%
  • tronTRON(TRX)$0.350293-5.51%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.030.85%
  • dogecoinDogecoin(DOGE)$0.098493-3.34%