Threats & Adversaries · Supply Chain
Developer Lure Becomes Supply-Chain Tampering A recruiter-style LinkedIn lure can be enough to reach the code pipeline. Once the attacker lands on a developer laptop, stolen credentials become the bridge into CI/CD and release systems, so the risk is not confined to the endpoint.
Wiz links these intrusions to JINX-0164, a previously unreported financially motivated actor active since at least mid-2025. The campaign used a credible LinkedIn contact, a fake meeting invite, custom macOS malware, and then access to internal code distribution and development infrastructure; in one case, internal source code was modified.
The forward risk is supply-chain tampering. If an attacker can touch build or release systems, downstream users may receive altered code even after the original laptop is cleaned up.
3 sources · May 28
Timeline Sources May 28 Infosecurity Magazine
New Threat Actor Jinx-0164 Targets Crypto Developers on macOS
New actor Jinx-0164 hit crypto developers with fake recruiter lures and macOS malware
original May 28 The Hacker News
JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware
JINX-0164 targeted cryptocurrency organizations using recruitment-themed social engineering and custom macOS malware to steal digital assets.
original May 27 Wiz Research
Threat Actor Targets Crypto Organizations | Wiz Blog | Wiz Blog
Threat actor, JINX-0164, uses LinkedIn social engineering, custom macOS malware, and CI/CD hijacking to target crypto organizations.
original Part of the PlainSec briefing for 2026-05-27
Every edition of this story: Developer Lure Becomes Supply-Chain Tampering
More from today
Threats & Adversaries · Supply Chain
Developer Lure Becomes Supply-Chain Tampering A recruiter-style LinkedIn lure can be enough to reach the code pipeline. Once the attacker lands on a developer laptop, stolen credentials become the bridge into CI/CD and release systems, so the risk is not confined to the endpoint.
Wiz links these intrusions to JINX-0164, a previously unreported financially motivated actor active since at least mid-2025. The campaign used a credible LinkedIn contact, a fake meeting invite, custom macOS malware, and then access to internal code distribution and development infrastructure; in one case, internal source code was modified.
The forward risk is supply-chain tampering. If an attacker can touch build or release systems, downstream users may receive altered code even after the original laptop is cleaned up.
3 sources · May 28
Timeline Sources May 28 Infosecurity Magazine
New Threat Actor Jinx-0164 Targets Crypto Developers on macOS
New actor Jinx-0164 hit crypto developers with fake recruiter lures and macOS malware
original May 28 The Hacker News
JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware
JINX-0164 targeted cryptocurrency organizations using recruitment-themed social engineering and custom macOS malware to steal digital assets.
original May 27 Wiz Research
Threat Actor Targets Crypto Organizations | Wiz Blog | Wiz Blog
Threat actor, JINX-0164, uses LinkedIn social engineering, custom macOS malware, and CI/CD hijacking to target crypto organizations.
original Part of the PlainSec briefing for 2026-05-27
Every edition of this story: Developer Lure Becomes Supply-Chain Tampering
More from today