A recruiter-style LinkedIn lure can be enough to reach the code pipeline. Once the attacker lands on a developer laptop, stolen credentials become the bridge into CI/CD and release systems, so the risk is not confined to the endpoint.
Wiz links these intrusions to JINX-0164, a previously unreported financially motivated actor active since at least mid-2025. The campaign used a credible LinkedIn contact, a fake meeting invite, custom macOS malware, and then access to internal code distribution and development infrastructure; in one case, internal source code was modified.
The forward risk is supply-chain tampering. If an attacker can touch build or release systems, downstream users may receive altered code even after the original laptop is cleaned up.