BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Cryptocriminal JINX-0164 Targets Macs in Sophisticated Supply Chain Heist

JINX-0164 targets crypto with macOS malware, fake jobs, and a poisoned npm supply chain.

  • A new financially motivated threat actor, tracked as JINX-0164, is actively targeting cryptocurrency organizations with sophisticated social engineering and custom macOS malware.
  • The campaign uses fake job offers and meeting invites to trick developers into installing an infostealer called AUDIOFIX, which steals credentials, SSH keys, and cryptocurrency wallet data.
  • The attacker has also executed a supply chain attack by compromising a legitimate npm package, @velora-dex/sdk, to distribute a separate Go-based backdoor called MiniRAT.
  • Researchers have noted similarities in tactics to North Korean hacking groups but have not found definitive infrastructure links connecting JINX-0164 to Pyongyang.

A previously unknown threat actor has been targeting cryptocurrency organizations since at least mid-2025, using recruitment-themed social engineering and custom macOS malware to steal digital assets, according to researchers from Wiz. The operation, designated JINX-0164, employs credible LinkedIn profiles to approach victims under the guise of a job opportunity.

- Advertisement -

The social engineering scheme leads to a fake teleconference website where victims download a malicious program. Consequently, a bash script fetches a Python-based infostealer and remote access trojan codenamed AUDIOFIX from a domain masquerading as an Apple driver store. “The payload masquerades as a system audio driver named coreaudiod,” Wiz explained.

This malware steals a wide range of sensitive data, including credentials from password managers, browser data, SSH keys, and active sessions for Discord and Telegram. Furthermore, AUDIOFIX allows the attacker to move laterally into internal development infrastructure and modify source code to compromise other systems.

In a parallel supply chain attack, the threat actor compromised the legitimate @velora-dex/sdk npm package. The poisoned version, as detailed by SafeDep and StepSecurity, delivered a Go-based backdoor called MiniRAT.

The campaign’s focus on cryptocurrency and use of specific VPN services echoes tactics of North Korean threat clusters like BlueNoroff. However, Wiz stated there are no current infrastructure overlaps definitively linking JINX-0164 to Pyongyang.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

BlackRock’s Bitcoin ETF Lures New Investors to Entire ETF Market

BlackRock's spot Bitcoin ETF has attracted a significant number of first-time ETF investors.Many of...

Audit Gap Exposed As AI Finds Major Four-Year Crypto Bug

A critical four-year-old bug in ZCash's shielded pool, discovered in June 2026, wiped out...

Z.ai’s GLM-5.2 Nears Claude Opus, Beats GPT-5.5, MIT Licensed

Z.ai released the GLM-5.2 AI model, which performs within 1% of Claude Opus 4.8...

Strategy loses 40 years of dividend coverage in 7 months

Strategy lost 40 years of forecasted dividend coverage in just seven months.The coverage decline...

HIVE to deploy GPUs for Cohere in $220M AI cloud deal

HIVE Digital Technologies has signed a major three-year GPU cloud contract with Bell AI...

Must Read

Best Crypto Audiobooks of 2026: The Ultimate Listen & Learn Guide

You can't read Bitcoin charts while driving 70 mph on the highway. You can't study Ethereum whitepapers during your morning run. But you can...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading