AI CRYPTO

Custom Malware Targeting Crypto Developers Uncovered by Wiz

Cybersecurity firm Wiz reveals that a hacker group known as JINX-0164 is using fake meeting invitations to deploy a custom macOS malware named AUDIOFIX, targeting crypto developers.

CoinSynaptic Desk
AI CRYPTO · Correspondent
· PUBLISHED JUN 6, 2026 · 2 MIN READ

A troubling trend has emerged in cryptocurrency development, with a hacker group known as JINX-0164 posing a significant threat. This group has been targeting crypto developers on LinkedIn, enticing them into fake meetings that lead to the installation of sophisticated macOS malware. A report from cloud security firm Wiz, published on May 27, 2026, reveals that the malware, named AUDIOFIX, is designed to steal sensitive credentials and hijack the pipelines developers use to build and deploy software.

Fake Meetings, Real Consequences

The attackers create profiles that appear legitimate, suggesting business calls with unsuspecting developers. They share links to counterfeit websites that mimic Microsoft Teams or other video conferencing tools. When a developer clicks on what they believe to be a meeting URL, AUDIOFIX silently begins its installation process. This malware operates on both Intel and Apple Silicon Macs, using scripts hosted on a fake Apple site.

Once installed, AUDIOFIX becomes a stealthy adversary. It collects saved passwords from the macOS Keychain, browser credentials, SSH keys, and cloud access tokens from major providers like AWS, GCP, and Azure. In a sophisticated twist, the attackers also directly phish for passwords, storing them in encoded files for future use.

A New Breed of Infostealer

What distinguishes JINX-0164 from other infostealers is its focus on internal code repositories and development infrastructures. Wiz has linked the group to a series of attacks dating back to mid-2025. In one documented case from early 2026, the attackers used stolen GitHub tokens to siphon secrets from CI/CD pipelines with an open-source tool called nord-stream. They injected AUDIOFIX malware into internal repositories, impersonating legitimate developers by forging Git commit metadata. This deception allowed them to push malicious code into main branches or hijack existing ones.

See also  Qualcomm Declares 2026 the Year of Autonomous AI Agents

The implications of this infiltration are severe. Developers who unknowingly pulled from these compromised repositories were infected automatically, turning their organization's development workflow into a distribution mechanism for malware.

GitHub's Vigilance

Fortunately, not all attempts at impersonation went unnoticed. GitHub’s Vigilant Mode, which flags commits lacking verified GPG signatures, caught the impersonation in at least one instance. This underscores the need for strong security measures within development environments, especially in the crypto sector where the stakes are high.

As the cryptocurrency market evolves, the tactics employed by groups like JINX-0164 serve as a stark reminder of the vulnerabilities in the industry. Developers must remain alert and implement stringent security protocols to safeguard their work and sensitive information from these growing threats. With malware like AUDIOFIX on the loose, the call for cybersecurity awareness in the crypto community has never been more urgent. The future of secure development practices will hinge on adopting proactive measures against such sophisticated attacks.

Quick answers

What is AUDIOFIX malware?

AUDIOFIX is a custom macOS malware that installs silently when a user clicks on a fake meeting link, stealing various credentials.

How does JINX-0164 operate?

JINX-0164 reaches out to developers via LinkedIn, inviting them to fake meetings that lead to malware infection.

What security measures can developers take?

Developers should implement stable security protocols, including using GitHub's Vigilant Mode to flag suspicious commits.

CoinSynaptic Desk

AI Crypto · 2,404 stories

CoinSynaptic Desk covers the intersection of artificial intelligence and decentralized networks — frontier AI infrastructure, crypto-native AI agents, Bittensor subnets, DePIN economies, and tokenized compute.

THE DAILY SIGNAL

The stories that move AI & crypto markets — before the market reacts.

Free. 7am ET. Five stories. 62,400 readers.