Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Myanmar’s Civilian Killings Escalate Amid Diplomatic Efforts

    July 29, 2026

    AI is Vietnam’s new capital magnet

    July 29, 2026

    76 Drums ft. JC Kalinks – Beauty Station (WOW) | Video

    July 28, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Myanmar’s Civilian Killings Escalate Amid Diplomatic Efforts
    • AI is Vietnam’s new capital magnet
    • 76 Drums ft. JC Kalinks – Beauty Station (WOW) | Video
    • We have to beat Argentina first
    • Donald Trump’s children appear to be grifting their way to nepo-billionaire status
    • Chad's population see census as solution to make grievances heard
    • FG’s new IPPIS human resource modules deepen civil service digital reforms
    • WAFCON 2026: CAF announce new ways to watch in Africa and worldwide
    X (Twitter) Instagram YouTube
    iFonge
    • Africa News
    • World News
    • Economy
    • Entertainment
    • Finance
    • Politics
    • sports
    iFonge
    Home » Mac malware campaign targets crypto coders — Arabian Post
    International News

    Mac malware campaign targets crypto coders — Arabian Post

    ifongeBy ifongeMay 29, 2026No Comments0 Views
    Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Mac malware campaign targets crypto coders — Arabian Post

    Cryptocurrency developers have become the focus of a new macOS-focused cyber campaign that uses fake recruiter approaches, malicious meeting links and compromised software pipelines to steal digital assets and spread malware through trusted internal systems.

    The activity is being tracked as JINX-0164, a previously unreported financially motivated threat actor active since at least mid-2025. Investigators found that the group has targeted cryptocurrency organisations by approaching developers and employees through credible LinkedIn profiles, then steering them towards bogus online meeting platforms or job-related technical tasks that lead to malware installation.

    The campaign marks a shift from conventional credential theft towards deeper attacks on development infrastructure. Once a developer’s workstation is compromised, the attacker seeks access to internal repositories, build systems and code distribution channels, turning the victim’s own engineering environment into a path for wider infection. At least one intrusion unfolded over about two weeks, beginning with social engineering and ending with malicious source-code changes designed to compromise additional endpoints.

    The malware at the centre of the campaign is AUDIOFIX, a Python-based macOS stealer and remote access trojan. It is delivered through scripts hosted on spoofed infrastructure that mimics trusted technology services, including fake Apple-related domains. The payload is built to run on both Intel and Apple Silicon machines, increasing its usefulness against developer teams that rely heavily on macOS laptops.

    After execution, AUDIOFIX attempts to gather credentials from macOS Keychain files, browser stores, password managers, local administrator accounts, SSH keys, configuration files, shell history and cryptocurrency wallet data. It also targets sessions from communications platforms such as Slack, Discord and Telegram, giving the attacker potential access to team discussions, engineering channels and operational details. Cloud secrets, including credentials linked to AWS, Google Cloud, Azure and Cloudflare, are also among the material sought.

    The attacker’s behaviour shows a particular interest in software development pipelines rather than broad cloud exploitation. Although some cloud sign-in attempts were observed, the primary objective appeared to be the abuse of Git repositories and CI/CD systems. In one case, the actor injected AUDIOFIX into internal repositories, altered committer names and email fields to impersonate other developers, pushed code directly to main branches where protections were weak, and hijacked existing branches when direct access was unavailable.

    This technique increases the risk of secondary infections because employees who pull code or build from compromised repositories may unknowingly execute the malware. It also creates a potential route into supply-chain attacks, where malicious code can be distributed through legitimate channels and appear to come from trusted internal teams.

    JINX-0164 has also been linked to MiniRAT, a Go-based backdoor distributed earlier through a compromised version of the npm package @velora-dex/sdk, a toolkit associated with decentralised finance activity. That episode underlined the wider risk facing Web3 and crypto developers, who often depend on open-source packages, automated builds and rapid deployment workflows.

    The campaign resembles tactics used by several North Korea-linked clusters that have targeted cryptocurrency workers through fake jobs, coding tests and video-call lures. However, investigators have not established enough evidence to link JINX-0164 to a state sponsor. The lack of infrastructure overlap with publicly tracked groups has kept attribution cautious, even though the sector focus and social-engineering methods are familiar to threat hunters.

    The use of recruiter themes remains effective because developers are accustomed to technical screening, code challenges and online meetings. Attackers exploit that routine by presenting malicious downloads as meeting fixes, drivers or project dependencies. The approach is particularly dangerous in cryptocurrency firms, where developer machines may hold wallet data, deployment keys, exchange credentials and access to sensitive repositories.

    The findings add to growing concern over developer workstations as part of the software supply chain. Security teams have traditionally focused on cloud environments, production servers and perimeter controls, but the campaign shows how a single laptop can become a bridge into source code, secrets and release systems. Strong branch protection, verified commits, hardware-backed keys, endpoint monitoring, restricted token scopes and tighter review of CI/CD secrets have become central defensive measures.

    For cryptocurrency firms, the immediate risk is not limited to stolen wallets. A compromised developer account can expose private repositories, internal tooling, customer-facing code and package publishing rights. That combination can allow attackers to move from individual theft to broader ecosystem compromise, especially where release pipelines lack separation of duties or where automated systems accept code changes with limited scrutiny.

    Arabian Campaign coders crypto Mac malware Post Targets
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    ifonge
    • Website
    • X (Twitter)
    • Instagram

    Related Posts

    Comercio Partners unveils over N100m women fund, targets African financial leadership

    July 27, 2026

    Houthi oil strikes test fragile US-Iran pause — Arabian Post

    July 26, 2026

    Singapore’s Tikva targets solid cancer barrier with US$8M Series A

    July 25, 2026

    Comments are closed.

    Top Posts

    Iran live updates: Trump vows ‘bigger, and better’ Iran attacks if deal not reached

    April 9, 202653

    Strait of Hormuz ‘completely open’, Iran says; Stock market continues its record-setting rally

    April 17, 202628

    Tyson Fury will pay unique tribute to Ricky Hatton in Makhmudov comeback fight

    April 10, 202617

    Trauma Bonding in Relationships and How Trauma Attachment, Abuse, and Emotional Dependence Form Hard to Break Bonds

    April 28, 202614
    Follow Us
    • Twitter
    • Instagram
    • YouTube

    Subscribe to Updates

    Get the latest news from iFonge.

    About Us
    About Us

    At Ifonge, we are dedicated to delivering high-quality content across multiple categories including National News, International News, Economy, Entertainment, Finance, Health, Lifestyle, Politics, and Sports.

    Our Picks

    Myanmar’s Civilian Killings Escalate Amid Diplomatic Efforts

    July 29, 2026

    AI is Vietnam’s new capital magnet

    July 29, 2026

    76 Drums ft. JC Kalinks – Beauty Station (WOW) | Video

    July 28, 2026
    Most Popular

    Iran live updates: Trump vows ‘bigger, and better’ Iran attacks if deal not reached

    April 9, 202653

    Strait of Hormuz ‘completely open’, Iran says; Stock market continues its record-setting rally

    April 17, 202628

    Tyson Fury will pay unique tribute to Ricky Hatton in Makhmudov comeback fight

    April 10, 202617
    © 2026 All rights reserved iFonge.
    • Home
    • About us
    • DISCLAIMER
    • Privacy Policy
    • Contact

    Type above and press Enter to search. Press Esc to cancel.