JINX-0164 is a previously unreported, financially motivated threat actor tracked by Wiz, active since at least mid-2025. The actor targets cryptocurrency organizations and cryptocurrency development infrastructure, with a particular focus on developers and software developers at financial firms. JINX-0164 uses recruitment-themed social engineering, including credible fake LinkedIn recruiter or business-contact profiles and fake virtual meeting invitations, to lure victims to spoofed teleconferencing sites that present technical-error prompts and instruct them to download malicious camera, audio, or driver 'fix' scripts. The group uses custom macOS malware, primarily AUDIOFIX and MINIRAT. AUDIOFIX is described as a compiled Python-based macOS infostealer and backdoor/RAT. It harvests Keychain data, browser credentials and history, local administrator credentials, SSH keys, configuration files, console history, cloud secrets including AWS, Azure, GCP, and Cloudflare credentials, active sessions from Slack, Discord, and Telegram, and cryptocurrency wallet data including wallet extensions and addresses. It has also been described as supporting command execution, payload retrieval, file deletion, reconnaissance, exfiltration, and lateral movement. MINIRAT is a lightweight Go-based backdoor associated with the same activity. JINX-0164 focuses on compromising internal code repositories, CI/CD pipelines, and enterprise deployment pipelines rather than broad cloud-resource abuse. Reported activity includes stealing GitHub tokens, exfiltrating GitHub Actions secrets, injecting malicious payloads into internal repositories and unverified branches, pushing malicious code to main branches when protections were absent, hijacking existing branches when direct access was blocked, and modifying Git committer name and email fields to impersonate legitimate developers. Infected shared repositories were used as a propagation mechanism to compromise additional developers who pulled and built malicious code. The actor has also conducted supply chain compromise. In at least one case, JINX-0164 trojanized npm package @velora-dex/sdk version 4.9.1 on April 7, 2026 by appending code to download a shell script that installed MINIRAT when the package was imported. Reporting states the corresponding GitHub source code was unchanged, suggesting compromise of npm credentials only. More broadly, the content states JINX-0164 uses both supply chain compromise and social engineering to disseminate malware targeting secrets from CI/CD pipelines. Some reporting notes similarities between JINX-0164 tradecraft and North Korean developer-targeting activity, including Contagious Interview- and BlueNoroff-like patterns, but the content also states analysts found no infrastructure overlap with previously documented state-sponsored groups and no direct infrastructure overlap tying JINX-0164 to North Korea. No other aliases or sub-groups are provided in the content.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
91 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses supply chain compromise and social engineering to spread malware aimed at stealing secrets from CI/CD pipelines.
A financially motivated cluster conducting targeted social-engineering attacks against software developers at financial firms, delivering macOS malware to steal credentials and compromise enterprise deployment pipelines, including npm supply-chain abuse.
Targets cryptocurrency organizations using recruitment-themed social engineering and custom malware to steal digital assets and sensitive developer information.
Financially motivated attacks against cryptocurrency organizations using LinkedIn social engineering, fake meeting pages, macOS malware, credential theft, developer impersonation, CI/CD secret theft, and software supply chain compromise via a trojanized npm package.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.