New Threat Actor Jinx-0164 Targets Crypto Developers on macOS (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- Attacks begin with LinkedIn lures, fake meetings, and Audiofix malware
- Audiofix steals keys, credentials, and crypto wallet data
- Stolen GitHub tokens used to compromise CI/CD pipelines
- npm package @velora-dex/sdk version 4.9.1 trojanized with MINIRAT backdoor
"A previously unreported threat actor, Jinx-0164, targets cryptocurrency firms with custom macOS malware, fake recruiter lures on LinkedIn, and hijacking of internal development pipelines. The malware, Audiofix, steals credentials, keys, and crypto wallet data."
#Jinx-0164
#macOS malware
#CI/CD compromise
no comments yet.