logo

Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure

ID: 8a51cbe1-e752-57e5-bcce-2c96dcc5fa2f

STIX ID: report--8a51cbe1-e752-57e5-bcce-2c96dcc5fa2f

Feed Name: Wiz Blog

Threat Score
78/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

Author: Shira Ayal

...
...

Wiz CIRT attributes a series of targeted intrusions against cryptocurrency organizations to a financially motivated actor cluster called JINX-0164. The actor used credible LinkedIn recruiter lures and fake conferencing/driver sites to deliver macOS payloads (AUDIOFIX, MINIRAT) via bash droppers, stole extensive developer and crypto credentials, moved laterally into CI/CD and code distribution systems, and conducted a supply-chain compromise of an npm SDK; the report provides technical analysis, IoCs (domains, hashes, file paths), and detection/response guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.