The JINX-0164 campaign is another reminder that cryptocurrency firms are being targeted through people and developer workflows, not just through exchanges, wallets, or blockchain infrastructure. According to the report, the threat actor used fake recruiter lures, credible LinkedIn profiles, rogue meeting domains, and custom macOS malware to target cryptocurrency organizations and developers.

This is especially dangerous because the attack begins like a normal recruitment conversation. Victims are invited to a virtual meeting, redirected to a fake conferencing site, and then tricked into downloading a supposed “fix” or driver. That download installs a Python-based macOS infostealer and remote access trojan called AUDIOFIX, which can steal credentials, SSH keys, password-manager data, iCloud Keychain files, browser data, crypto wallet information, and active Slack, Discord, and Telegram sessions. 

The campaign also shows how endpoint compromise can turn into supply-chain compromise. Researchers found that JINX-0164 used compromised employee laptops to move laterally into code distribution systems, development infrastructure, and CI/CD environments. In at least one case, the actor attempted to modify source code and spread malware further. Because apparently one poisoned job interview can now become a software supply-chain incident. 
Cryptocurrency companies should treat recruitment-themed outreach, fake meeting platforms, and developer downloads as high-risk scenarios. Teams should verify recruiter identities, avoid installing meeting “fixes,” restrict developer laptop privileges, monitor unusual launch agents and macOS persistence, rotate exposed credentials, and protect CI/CD systems with least privilege and strong access controls.

The broader lesson is simple: attackers are targeting the people who build and move digital assets. macOS systems, developer workstations, password managers, SSH keys, messaging sessions, and CI/CD pipelines are all part of the modern attack surface. In crypto environments, one compromised developer machine can expose far more than one laptop. It can become the bridge to wallets, infrastructure, code, and customer trust.


A new campaign orchestrated by a previously undocumented threat actor has targeted cryptocurrency organizations with an aim to facilitate digital asset theft using recruitment-themed social engineering and bespoke macOS malware. "These campaigns leveraged sophisticated social engineering techniques, custom macOS malware, and deep targeting of CI/CD infrastructure," Wiz researchers Shira Ayal,

Source: JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware via The Hacker News — published 28 May 2026.