Wiz disclosed a financially motivated threat actor tracked as JINX-0164 that has targeted cryptocurrency organizations since at least mid-2025 by impersonating recruiters on LinkedIn and directing developers to fake virtual meetings hosted on spoofed domains. Victims were tricked into downloading AUDIOFIX, a Python-based macOS infostealer and remote access trojan that enabled credential theft, collection of cloud secrets, and access to internal development environments. In one documented intrusion, the actor pivoted from an employee workstation into code repositories and CI/CD systems, then modified source code to further malware propagation and support cryptocurrency theft.
Researchers also linked JINX-0164 to a supply-chain compromise of the npm package @velora-dex/sdk on April 7, 2026, which delivered the Go-based MINIRAT backdoor. The campaign used spoofed infrastructure and VPN services including Mullvad, Astrill, and ExpressVPN, as well as tooling such as nord-stream to exfiltrate GitHub Actions secrets. While the tradecraft overlaps with cryptocurrency-focused North Korean activity such as UNC1069 and Sapphire Sleet, Wiz said there is not yet sufficient evidence to attribute JINX-0164 to a specific state sponsor.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
Intrinsec reported that in March and April 2026, threat actors ran malicious spam campaigns delivering a heavily obfuscated JavaScript backdoor via ZIP or RAR attachments to targets in several countries and sectors.
Wiz said the previously untracked threat actor JINX-0164 has been active since at least mid-2025, using recruiter-themed social engineering to target developers at cryptocurrency firms and steal cryptocurrency-related assets.
In an early-2026 intrusion highlighted by Wiz, the actor used a malicious conferencing lure to install AUDIOFIX on macOS, steal credentials and cloud secrets, pivot into code repositories and CI/CD systems, and modify source code in pursuit of cryptocurrency theft.
Wiz disclosed the JINX-0164 campaign, detailing its fake recruiter lures, spoofed domains, AUDIOFIX macOS malware, MINIRAT linkage, and stating that similarities to North Korean tradecraft were insufficient for attribution.
Wiz linked JINX-0164 to a supply-chain attack on the npm package @velora-dex/sdk that delivered the Go-based MINIRAT backdoor.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 105 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
8 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcecyber.netsecops.io
Open sourcewiz.io
Open sourcethreats.wiz.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.