www.wiz.io New Threat Actor JINX-0164 Targets Cryptocurrency Organizations
Article Content
- •JINX-0164 targets cryptocurrency organizations using sophisticated social engineering.
- •The group employs custom macOS malware named Audiofix to steal sensitive credentials.
- •Infections spread through compromised development pipelines and trojanized npm packages.
A new threat actor, JINX-0164, has been identified targeting cryptocurrency firms using custom macOS malware and social engineering tactics. Active since mid-2025, the group employs fake recruiter approaches to gain initial access. Victims are invited to virtual meetings on lookalike domains, where malware is installed under the guise of a technical fix. The malware, named Audiofix, is capable of stealing sensitive information such as credentials and cryptocurrency wallet details. JINX-0164 has also hijacked internal development pipelines, injecting malicious code into repositories, leading to further infections. The group has been linked to multiple incidents, including the trojanization of npm packages. Security experts recommend monitoring for specific indicators of compromise and enhancing logging practices. The threat remains active as of May 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (14)
Following this threat?
Track Jinx-0164, Audiofix and Bitget in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…