JINX-0164 is a financially motivated threat actor active since at least mid-2025 that targets cryptocurrency organizations and related development infrastructure. The group is known for recruitment-themed social engineering, particularly the use of fake recruiter or business-contact personas on professional networking platforms to lure software developers into fraudulent virtual meetings and trick them into executing malicious macOS payloads. JINX-0164 has also conducted software supply chain compromise, including the trojanization of a public npm package to deliver a backdoor. The actor’s operations focus on developers, CI/CD environments, internal code repositories, and software distribution workflows rather than broad cloud-resource abuse. After initial compromise, JINX-0164 steals credentials, SSH keys, cloud and package-management secrets, communication-platform sessions, and cryptocurrency wallet-related data. Reported malware associated with the cluster includes AUDIOFIX, a macOS infostealer and backdoor, and MINIRAT, a lightweight Go-based backdoor. The group has used stolen GitHub access and CI/CD secrets to move deeper into victim environments, exfiltrate secrets from pipelines, and tamper with internal repositories. JINX-0164 has been observed modifying commit metadata to impersonate legitimate developers, injecting malicious payloads into unverified or insufficiently protected branches, and using compromised development workflows as a propagation mechanism so that other employees become infected when pulling and building altered code. In at least one supply chain incident, the actor appears to have compromised package-publishing credentials without altering the corresponding source repository, indicating a targeted attack on release infrastructure. The actor’s tradecraft overlaps in some respects with North Korean developer-targeting activity, but available reporting does not establish a confirmed state attribution and notes no direct infrastructure overlap with previously documented state-sponsored groups.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
40 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
91 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses supply chain compromise and social engineering to spread malware aimed at stealing secrets from CI/CD pipelines.
Uses supply chain compromise and social engineering to spread malware targeting CI/CD secrets.
A financially motivated cluster conducting targeted social-engineering attacks against software developers at financial firms, delivering macOS malware to steal credentials and compromise enterprise deployment pipelines, including npm supply-chain abuse.
Targets cryptocurrency organizations using recruitment-themed social engineering and custom malware to steal digital assets and sensitive developer information.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.