Threats · 109 days ago

Developer Lure Becomes Supply-Chain Tampering

A recruiter-style LinkedIn lure can be enough to reach the code pipeline. Once the attacker lands on a developer laptop, stolen credentials become the bridge into CI/CD and release systems, so the risk is not confined to the endpoint.

Wiz links these intrusions to JINX-0164, a previously unreported financially motivated actor active since at least mid-2025. The campaign used a credible LinkedIn contact, a fake meeting invite, custom macOS malware, and then access to internal code distribution and development infrastructure; in one case, internal source code was modified.

The forward risk is supply-chain tampering. If an attacker can touch build or release systems, downstream users may receive altered code even after the original laptop is cleaned up.

Timeline

Sources

3 sources covering this story

Entities

Part of the PlainSec briefing for 2026-05-28

Editions

Related stories