Minacce · 125 giorni fa
Un’esca in stile recruiter su LinkedIn può essere sufficiente per raggiungere la code pipeline. Una volta che l’attaccante atterra su un laptop di uno sviluppatore, le credenziali rubate diventano il ponte verso CI/CD e i sistemi di release, quindi il rischio non è confinato all’endpoint.
3 fonti che coprono questa storia
JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware
JINX-0164 targeted cryptocurrency organizations using recruitment-themed social engineering and custom macOS malware to steal digital assets.
New Threat Actor Jinx-0164 Targets Crypto Developers on macOS
New actor Jinx-0164 hit crypto developers with fake recruiter lures and macOS malware
Threat Actor Targets Crypto Organizations | Wiz Blog | Wiz Blog
Threat actor, JINX-0164, uses LinkedIn social engineering, custom macOS malware, and CI/CD hijacking to target crypto organizations.
Part of the PlainSec briefing for 2026-05-28