logo

JINX-0164 Targeting Cryptocurrency Development Infrastructure (Campaign)

ID: 9014d6a0-933a-5b2c-8052-95968849cdd5

STIX ID: report--9014d6a0-933a-5b2c-8052-95968849cdd5

Feed Name: Wiz Cloud Threat Landscape

Threat Score
78/100

Date Published: 2026-05-27

Date Updated: 2026-05-29

Author: [email protected] (Wiz Threat Research)

...
...

Wiz Research observed an active, organized campaign targeting cryptocurrency development infrastructure and developer workflows using social engineering (fake business outreach and malicious meeting invitations), trojanized npm packages, and malware (AUDIODFX stealer and MINIRAT backdoor) to exfiltrate browser credentials, crypto wallets, cloud credentials, SSH keys, and CI/CD secrets; attackers also used stolen credentials to access GitHub repositories and attempted to overwrite GitHub Actions secrets while leveraging VPNs and residential proxies to obscure activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.