Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

NeoPod AMA with Pixudi founder set for Aug. 5

August 5, 2026

Hyperliquid burns $1.27B HYPE as AQAv2 expands buyback engine: Can demand absorb supply?

August 5, 2026

Trump-linked Bitcoin firm reaches $2.5M settlement with DOJ over pandemic loan

August 5, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»New Threat Actor Jinx-0164 Targets Crypto Developers on macOS
New Threat Actor Jinx-0164 Targets Crypto Developers on macOS
Security and Privacy

New Threat Actor Jinx-0164 Targets Crypto Developers on macOS

May 28, 2026No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A previously unreported threat actor has been observed targeting cryptocurrency firms with custom macOS malware, fake recruiter approaches and the hijacking of internal development pipelines.

Wiz has attributed the activity to a financially motivated cluster, now tracked as Jinx-0164, according to new analysis from the company.

Active since at least mid-2025 and focused almost entirely on macOS, the actor shares techniques with North Korean groups such as UNC1069, also known as Sleet. However, it implements these techniques differently and shows no infrastructure overlap with tracked actors. Wiz stopped short of linking it to any state-sponsored threat actor. 

Fake Meetings and a Cloned Audio Driver

The intrusions typically begin on LinkedIn, where the attacker poses as a business contact or recruiter using a credible profile. The target is invited to a virtual meeting on a lookalike domain impersonating a service such as Microsoft Teams.

Joining the call triggers a fake technical fault and a prompt to run a “fix,” which installs the malware. The payload, a Python-based stealer and remote access tool named Audiofix, masquerades as a system audio driver and runs on both Intel and Apple Silicon machines.

Audiofix harvests Keychain contents, browser credentials, SSH keys, cloud provider keys and details from 51 cryptocurrency wallet extensions.

It also hijacks Discord, Slack and Telegram sessions and monitors the clipboard for copied wallet addresses.

From Laptops to Code Pipelines

Rather than pivoting into cloud accounts, Jinx-0164 turned harvested GitHub tokens against the victim’s development infrastructure, using the open-source tool nord-stream to pull secrets from CI/CD pipelines.

It then injected Audiofix into internal repositories, disguising commits under other developers’ names and pushing them to main or existing branches.

See also  Are perps swaps? A quick look at that CME suit: State of Crypto

When colleagues built from the poisoned repositories, their machines were infected too, turning the build process into a propagation channel. Wiz said GitHub’s Vigilant Mode, which flags unverified commits, helped expose the impersonation and halt the spread.

Read more on North Korean groups: Hackers Use Deepfake Video Calls to Target Crypto Firms

The group’s reach has extended beyond direct intrusions. On April 7, it trojanized version 4.9.1 of the npm package @velora-dex/sdk, a widely used decentralized exchange toolkit, appending code that fetched a second macOS backdoor called MINIRAT.

The recruitment-themed lure is itself well established among crypto-focused attackers, echoing earlier campaigns by groups such as Slow Pisces.

Wiz urged defenders to watch for the published indicators of compromise, unexpected use of VPN services including Mullvad, Astrill and ExpressVPN, and secret exfiltration from CI/CD workflows.

It also advised enabling logs that are off by default, such as GitHub IP logging, and treating unverified commits as suspect.

Image credit: alexgo.photography / Shutterstock.com

Source link

actor Crypto Developers Jinx0164 macOS Targets threat
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Senate has hours to advance CLARITY, but Bitwise says missing deadline sets up a crypto rally

August 5, 2026

Talos Integrates with STS Digital to Bring Institutional Crypto Options and Spot Liquidity to its Provider Network

August 5, 2026

Bessent’s top crypto adviser Tyler Williams exits US Treasury: Report

August 5, 2026

The crypto project trying to replace the US banking system just pulled its 10 trillion token filing

August 5, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

U.S. SEC Officially Acknowledges BlackRock’s Bitcoin Spot ETF Application, Kicking Off Review Process: Report

July 15, 2023

SEC Objects to Terraform’s $166M Retainer of Law Firm Dentons: Reuters

March 2, 2024

PayPal Unveils Groundbreaking Strategy to Green Bitcoin Mining

April 23, 2024

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

NeoPod AMA with Pixudi founder set for Aug. 5

August 5, 2026

Hyperliquid burns $1.27B HYPE as AQAv2 expands buyback engine: Can demand absorb supply?

August 5, 2026

Trump-linked Bitcoin firm reaches $2.5M settlement with DOJ over pandemic loan

August 5, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$64,580.000.40%
  • ethereumEthereum(ETH)$1,887.430.00%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$598.651.00%
  • usd-coinUSDC(USDC)$1.000.00%
  • rippleXRP(XRP)$1.07-1.40%
  • solanaSolana(SOL)$74.160.20%
  • tronTRON(TRX)$0.327706-0.60%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.021.10%
  • HyperliquidHyperliquid(HYPE)$57.462.90%