Threats · 109 days ago
A recruiter-style LinkedIn lure can be enough to reach the code pipeline. Once the attacker lands on a developer laptop, stolen credentials become the bridge into CI/CD and release systems, so the risk is not confined to the endpoint.
Wiz links these intrusions to JINX-0164, a previously unreported financially motivated actor active since at least mid-2025. The campaign used a credible LinkedIn contact, a fake meeting invite, custom macOS malware, and then access to internal code distribution and development infrastructure; in one case, internal source code was modified.
The forward risk is supply-chain tampering. If an attacker can touch build or release systems, downstream users may receive altered code even after the original laptop is cleaned up.
3 sources covering this story
JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware
JINX-0164 targeted cryptocurrency organizations using recruitment-themed social engineering and custom macOS malware to steal digital assets.
New Threat Actor Jinx-0164 Targets Crypto Developers on macOS
New actor Jinx-0164 hit crypto developers with fake recruiter lures and macOS malware
Threat Actor Targets Crypto Organizations | Wiz Blog | Wiz Blog
Threat actor, JINX-0164, uses LinkedIn social engineering, custom macOS malware, and CI/CD hijacking to target crypto organizations.
Part of the PlainSec briefing for 2026-05-28