BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Cryptocriminal JINX-0164 Targets Macs in Sophisticated Supply Chain Heist

JINX-0164 targets crypto with macOS malware, fake jobs, and a poisoned npm supply chain.

  • A new financially motivated threat actor, tracked as JINX-0164, is actively targeting cryptocurrency organizations with sophisticated social engineering and custom macOS malware.
  • The campaign uses fake job offers and meeting invites to trick developers into installing an infostealer called AUDIOFIX, which steals credentials, SSH keys, and cryptocurrency wallet data.
  • The attacker has also executed a supply chain attack by compromising a legitimate npm package, @velora-dex/sdk, to distribute a separate Go-based backdoor called MiniRAT.
  • Researchers have noted similarities in tactics to North Korean hacking groups but have not found definitive infrastructure links connecting JINX-0164 to Pyongyang.

A previously unknown threat actor has been targeting cryptocurrency organizations since at least mid-2025, using recruitment-themed social engineering and custom macOS malware to steal digital assets, according to researchers from Wiz. The operation, designated JINX-0164, employs credible LinkedIn profiles to approach victims under the guise of a job opportunity.

- Advertisement -

The social engineering scheme leads to a fake teleconference website where victims download a malicious program. Consequently, a bash script fetches a Python-based infostealer and remote access trojan codenamed AUDIOFIX from a domain masquerading as an Apple driver store. “The payload masquerades as a system audio driver named coreaudiod,” Wiz explained.

This malware steals a wide range of sensitive data, including credentials from password managers, browser data, SSH keys, and active sessions for Discord and Telegram. Furthermore, AUDIOFIX allows the attacker to move laterally into internal development infrastructure and modify source code to compromise other systems.

In a parallel supply chain attack, the threat actor compromised the legitimate @velora-dex/sdk npm package. The poisoned version, as detailed by SafeDep and StepSecurity, delivered a Go-based backdoor called MiniRAT.

The campaign’s focus on cryptocurrency and use of specific VPN services echoes tactics of North Korean threat clusters like BlueNoroff. However, Wiz stated there are no current infrastructure overlaps definitively linking JINX-0164 to Pyongyang.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Polymarket VP: No Mandatory KYC on Main Platform

Polymarket's engineering VP clarifies KYC is only for a new beta product's early test...

Shiba Inu Hits Yearly Low, Faces 37% Drop Prediction

Shiba Inu (SHIB) hit a yearly low of $0.000005236, declining nearly 5% amid a...

Bitcoin falls below $73,000 on heavy ETF outflows

Bitcoin fell to $72,885, its lowest level since mid-April, amid heavy leveraged position liquidations...

Bitcoin longs defend $70K despite ETF outflow worries

Bullish traders are opening new long positions to defend Bitcoin's support near $70,000, evidenced...

UK Sanctions HTX-Linked Entity for Russia Financial Services

The UK sanctioned Panamanian entity Huobi Global S.A. for allegedly providing financial services to...

Must Read

Top 5 Best Crypto Faucets To Earn Free Crypto This Year

QUICK LINKSWhat Are Crypto Faucets and How Do They Work?How Do Crypto Faucets Make Money?What to Expect: Realistic EarningsThe Best Crypto Faucets of 2025:...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading