Threats & Adversaries · Supply Chain

Developer Lure Becomes Supply-Chain Tampering

A recruiter-style LinkedIn lure can be enough to reach the code pipeline. Once the attacker lands on a developer laptop, stolen credentials become the bridge into CI/CD and release systems, so the risk is not confined to the endpoint.

Wiz links these intrusions to JINX-0164, a previously unreported financially motivated actor active since at least mid-2025. The campaign used a credible LinkedIn contact, a fake meeting invite, custom macOS malware, and then access to internal code distribution and development infrastructure; in one case, internal source code was modified.

The forward risk is supply-chain tampering. If an attacker can touch build or release systems, downstream users may receive altered code even after the original laptop is cleaned up.

3 sources · May 28

Timeline

Sources

Part of the PlainSec briefing for 2026-05-28

Every edition of this story: Developer Lure Becomes Supply-Chain Tampering

More from today