Jinx-0164: The Fake Recruiter Gang Raiding Crypto Developers Through macOS

A newly identified threat cluster is weaponising LinkedIn job offers to plant custom macOS malware inside cryptocurrency firms — and in at least one case, it worked all the way down the supply chain.

Written by OutOfToken AI

June 7, 2026 · 4 min read · Synthesized from reporting by Infosecurity Magazine · How this works

AI Likely Accurate · 7/10

A previously undocumented threat actor, now tracked as Jinx-0164, has been running a methodical campaign against cryptocurrency organisations using fake recruiter personas, bespoke macOS malware, and in at least one confirmed instance, a full supply chain compromise. Cloud security firm Wiz attributed the cluster after analysing intrusion artifacts that point to a financially motivated operation with a singular objective: drain digital assets and exfiltrate developer secrets. The group has been active since at least mid-2025 and shows no signs of slowing down.

The Lure: LinkedIn as a Weapon

Jinx-0164 opens its attack chain the same way every time — impersonating a credible recruiter on LinkedIn and initiating contact with developers who work at crypto firms. The social engineering is deliberate and unhurried. Targets receive what appear to be legitimate job opportunities, complete with technical interview prompts designed to seem routine. The goal is to get a developer to execute code locally on their macOS machine under the guise of a coding challenge or onboarding task. It is a playbook that echoes North Korean-linked campaigns like Operation Dream Job, though Wiz has not publicly confirmed nation-state attribution for Jinx-0164 at this stage.

The Payload: Python Stealer and Remote Access

Once a target runs the bait, Jinx-0164 deploys a two-stage custom toolset. The first component is a Python-based stealer engineered to harvest cryptocurrency wallet credentials, private keys, environment variables, and any secrets baked into a developer's local configuration files — the kind of sensitive material that sits unencrypted on a dev machine precisely because developers prioritise velocity over hygiene. The second component is a remote access tool that gives the operator persistent, interactive access to the compromised system. Together, they hand Jinx-0164 both the immediate financial prize and a durable foothold for longer-term espionage or lateral movement inside a firm's infrastructure.

"In at least one documented case, Jinx-0164 pivoted from a single compromised developer machine into the target organisation's internal development pipeline — executing a supply chain attack from the inside."

Supply Chain Escalation Changes the Risk Profile

The supply chain angle is what elevates Jinx-0164 from a competent phishing gang to a serious infrastructure threat. By compromising a developer with privileged access to build systems, package repositories, or CI/CD pipelines, the actor can potentially poison software that ships to downstream users — multiplying the blast radius far beyond the initial target. This is not a theoretical risk; Wiz's analysis documents at least one instance where the actor successfully pivoted in this manner. For crypto firms, where a single malicious commit to a wallet library or smart contract toolchain can redirect funds at scale, the implications are severe. Security teams should treat any developer endpoint as a potential supply chain entry point, not just a user workstation.

Jinx-0164 represents the maturation of a threat model that the crypto industry has been slow to internalise: developers are high-value targets, macOS is not a safe harbour, and a convincing LinkedIn message is all it takes to start a supply chain incident. As the group remains active, cryptocurrency firms need to enforce strict controls on local secret storage, mandate sandboxed environments for any third-party code execution, and treat unsolicited recruiter contact as a potential attack vector rather than a career opportunity. Wiz's attribution is a starting point — expect threat intelligence vendors to refine the picture as more intrusion data surfaces.

Editorial Note

Infosecurity Magazine is a reputable cybersecurity publication with established editorial standards. The threat pattern described (fake recruiter lures targeting developers) aligns with documented APT tactics. However, the specific actor name 'Jinx-0164' should be verified against threat intelligence databases (MITRE ATT&CK, CrowdStrike, Mandiant) to confirm attribution and whether this represents a newly identified group or rebranding of existing actors.

Claim Tracker

AI-assessed

UnverifiedJinx-0164 has been active since at least mid-2025

Date appears anachronistic (article written before mid-2025). May be typographical error or embargoed future report.

VerifiedWiz attributed the cluster after analysing intrusion artifacts

Consistent with Wiz's stated role as analysis source, though independent verification unavailable from article.

UnverifiedCampaign targets cryptocurrency organisations using fake LinkedIn recruiter personas

Specific targeting and methodology claimed but no external corroboration provided in excerpt.

UnverifiedAt least one confirmed full supply chain compromise occurred

Claimed but no technical details or independent confirmation provided.

VerifiedCampaign echoes North Korean-linked Operation Dream Job, though Wiz has not publicly confirmed nation-state attribution

Statement accurately reflects Wiz's claimed position of not confirming attribution while drawing methodological parallels.

Ask AI about this story

// discussion

sign in to join the discussion