A group of hackers, named JINX-0164, has been contacting crypto devs via LinkedIn and inviting them to fake meetings that infect of their machines with malware.A group of hackers, named JINX-0164, has been contacting crypto devs via LinkedIn and inviting them to fake meetings that infect of their machines with malware.

JINX-0164 hijacks crypto developer machines through phony meeting links

2026/06/06 13:26
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

A group of hackers, known as JINX-0164, has been contacting crypto developers via LinkedIn and inviting them to fake meetings that lead to the infection of their machines with custom macOS malware.

The malware steals login credentials and hijacks the pipelines developers use to build and deploy software. Cloud security firm Wiz published its findings on May 27, 2026.

Fake meeting link drops AUDIOFIX malware on devs machines

Wiz’s incident response team linked the group to attacks going back to at least mid of 2025.

Attackers reach out to a developer on LinkedIn using a profile that looks legitimate, suggest a business call, and send a link to a fake website made to look like Microsoft Teams or a similar video conferencing tool.

AUDIOFIX is the macOS virus that silently starts installation when a victim clicks on what they believe to be a meeting URL. It operates on Intel and Apple Silicon Macs and is delivered via a script stored on a fake Apple site. The virus sets itself up to continue operating after a restart, poses as a system audio component, and interacts with the attackers over HTTPS.

Once it is on the machine, it collects saved passwords from the macOS Keychain, browser credentials, SSH keys, cloud access tokens for AWS, GCP, and Azure, and crypto wallet data. Additionally, Wiz discovered that the attackers were directly phishing for passwords and storing them in encoded files.

Crypto devs fall for fake LinkedIn calls, lose control of code pipelines.Source: WIZ.

JINX-0164 differs from other infostealers because it goes after internal code repositories and development infrastructure.

In a case study from early 2026, Wiz documented how the attackers used stolen GitHub tokens to extract secrets from CI/CD pipelines with an open-source tool called nord-stream. They then injected their AUDIOFIX malware into internal repositories, impersonating legitimate developers by forging Git commit metadata and pushing malicious code to main branches or hijacking existing ones.

Other developers who pulled and built from those poisoned repos got infected automatically. The organization’s own development workflow became the distribution mechanism. GitHub’s Vigilant Mode, which flags commits lacking verified GPG signatures, caught the impersonation in at least one case.

The group also carried out a confirmed supply chain attack on a public npm package. On April 7, 2026, JINX-0164 trojanized version 4.9.1 of @velora-dex/sdk, injecting a base64-encoded command that fetched and executed a remote script deploying MINIRAT. That’s a lightweight Go-based backdoor focused on persistence and remote command execution.

Attackers target cash and code from crypto devs

AUDIOFIX and MINIRAT share command-and-control domains like datahub[.]ink, cloud-sync[.]online, and byte-io[.]us. The attackers route their activity through Mullvad VPN, Astrill VPN, and ExpressVPN to hide their real location.

Wiz found some tactical similarities with North Korean threat clusters UNC1069 and Sapphire Sleet, but found no direct infrastructure overlap. They’re calling JINX-0164 a distinct and financially motivated threat actor.

In May, hackers compromised 170+ npm and PyPI packages, including the official Mistral AI Python library. That attack exposed GitHub tokens and cloud credentials owned by crypto and AI developers. This was also the first documented case of malicious packages carrying valid SLSA Build Level 3 provenance attestations, breaking the cryptographic trust model meant to verify build integrity.

Hacking crypto and AI developers usually leads to cash and valuable code. Crypto labs/companies should strengthen cybersecurity measures and review their CI/CD pipelines for any unauthorized access or malicious activities. Unauthorized GitHub actions, commits with unverified signatures and unusual VPN connections are all warning signs. Developers who joined meetings sent via LinkedIn should scan their computers for viruses.

The smartest crypto minds already read our newsletter. Want in? Join them.

Predict & Trade to Win Rewards

Predict & Trade to Win RewardsPredict & Trade to Win Rewards

Guaranteed rewards with $500,000 prize pool

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Adoption Leads Traders to Snorter Token

Adoption Leads Traders to Snorter Token

The post Adoption Leads Traders to Snorter Token appeared on BitcoinEthereumNews.com. Largest Bank in Spain Launches Crypto Service: Adoption Leads Traders to Snorter Token Sign Up for Our Newsletter! For updates and exclusive offers enter your email. Leah is a British journalist with a BA in Journalism, Media, and Communications and nearly a decade of content writing experience. Over the last four years, her focus has primarily been on Web3 technologies, driven by her genuine enthusiasm for decentralization and the latest technological advancements. She has contributed to leading crypto and NFT publications – Cointelegraph, Coinbound, Crypto News, NFT Plazas, Bitcolumnist, Techreport, and NFT Lately – which has elevated her to a senior role in crypto journalism. Whether crafting breaking news or in-depth reviews, she strives to engage her readers with the latest insights and information. Her articles often span the hottest cryptos, exchanges, and evolving regulations. As part of her ploy to attract crypto newbies into Web3, she explains even the most complex topics in an easily understandable and engaging way. Further underscoring her dynamic journalism background, she has written for various sectors, including software testing (TEST Magazine), travel (Travel Off Path), and music (Mixmag). When she’s not deep into a crypto rabbit hole, she’s probably island-hopping (with the Galapagos and Hainan being her go-to’s). Or perhaps sketching chalk pencil drawings while listening to the Pixies, her all-time favorite band. This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Center or Cookie Policy. I Agree Source: https://bitcoinist.com/banco-santander-and-snorter-token-crypto-services/
Share
BitcoinEthereumNews2025/09/17 23:45
GOP insider shocks by debunking Republican conspiracy theory: 'What kind of sorcery?'

GOP insider shocks by debunking Republican conspiracy theory: 'What kind of sorcery?'

A California Republican operative went viral this week for doing something unusual in her party: publicly fact-checking a right-wing election conspiracy theory —
Share
Rawstory2026/06/07 08:55
Sovereign Bitcoin Holdings Linked to Bhutan Continue Declining Amid Structured Sell-Off

Sovereign Bitcoin Holdings Linked to Bhutan Continue Declining Amid Structured Sell-Off

TLDR: Bhutan-linked wallets moved 738 BTC worth $44.8M, continuing a structured sovereign drawdown pattern. Transfers occurred in mid-sized tranches, indicating
Share
Blockonomi2026/06/07 08:31

RealStocks Now Live

RealStocks Now LiveRealStocks Now Live

Trade real U.S. stock via regulated brokerage