logo

New Threat Actor Jinx-0164 Targets Crypto Developers on macOS

ID: 2b22bc5a-029c-521f-bb85-d432aa46d2ef

STIX ID: report--2b22bc5a-029c-521f-bb85-d432aa46d2ef

Feed Name: Infosecurity Magazine (News)

Threat Score
80/100

Date Published: 2026-05-28

Date Updated: 2026-05-28

...
...

Wiz reports a financially motivated cluster dubbed Jinx-0164 targeting crypto firms since at least mid-2025 using LinkedIn-based social engineering and fake meeting domains to install a Python-based macOS stealer/RAT (Audiofix) that harvests credentials and keys; the group also abused stolen GitHub tokens to exfiltrate CI/CD secrets and inject poisoned commits, and trojanized an npm package to deliver a second backdoor (MINIRAT), creating a high-risk supply-chain and developer-pipeline propagation vector.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.