Also known as: tracked as, Sleet
JINX-0164 (also tracked as Sleet) emerges as a financially driven adversary that concentrates on the cryptocurrency sector, specifically targeting development teams and build infrastructures. Their techniques center on social engineering through LinkedIn recruiter personas, delivering malicious macOS installers that deploy RATs like AUDIOFIX—a Python-based infostealer—and MINIRAT—a lightweight Go backdoor. Once initial access is achieved, the attackers harvest credentials from password managers, browser extensions, and local development tools, then pivot into repository environments to inject malicious code or tamper with CI/CD pipelines. The group’s supply‑chain tactics were demonstrated in April 2026 when they compromised a legitimate npm package (@velora-dex/sdk) to propagate malware across the community. Their operations also make extensive use of VPN services for IP obfuscation, and they employ advanced lateral movement techniques such as token impersonation, process injection, and exploitation of Apple’s inter‑process communication mechanisms. This combination of endpoint compromise, credential harvesting, and supply‑chain infiltration makes JINX-0164 a high‑risk actor for any organization with a crypto development footprint.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
JINX-0164 is a financially motivated threat actor that has been exploiting cryptocurrency development environments since mid‑2025. Using recruiter-themed LinkedIn social engineering, the group deploys custom macOS RATs such as AUDIOFIX and MINIRAT to steal wallet credentials, cloud secrets, and GitHub tokens before pivoting into CI/CD pipelines for supply‑chain compromise. The actor’s operations are sophisticated, combining credential harvesting from password managers with covert command‑and‑control over VPN tunnels.
Goals & Targeting
JINX-0164 is motivated by monetary gain and selects victims that possess high-value digital assets or infrastructure capable of generating revenue. Their primary focus on cryptocurrency developers, wallets, exchanges, and cloud services allows them to capture wallet credentials, API tokens, and proprietary code that can be monetized directly (via theft) or leveraged to facilitate secondary attacks against the broader financial and critical‑infrastructure sectors listed in their target profile. The actor’s use of recruiter‑themed social engineering enables low‑cost initial access points into privileged development environments, while the subsequent pivot into CI/CD pipelines expands the attack surface for lateral movement.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since its first reported activity in mid‑2025, JINX-0164 has maintained an opportunistic pace of operations, targeting high‑value repositories and development machines across the United States, Russia, Iran, Mexico, and Spain. The actor typically begins with a recruiter‑themed phishing lure delivered via LinkedIn, then deploys macOS RATs to establish footholds. After credential harvesting, they pivot into CI/CD environments or inject malicious code into public npm packages, allowing widespread propagation with minimal effort. Notably, the April 2026 npm attack demonstrated their capability for large‑scale supply‑chain compromise and highlighted a pattern of leveraging third‑party package ecosystems as a fast delivery vector.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on the SOC Prime article and Malpedia actor profile, both published in May‑August 2026. While these sources provide solid evidence of phishing via LinkedIn, macOS RAT deployment, and supply‑chain tactics, detailed timestamps for first/last seen are missing and some technique mappings rely on inference from related MITRE ATT&CK updates. Confidence is high regarding the attacker’s target profile, motivation, and core capabilities; moderate confidence for the full list of ATT&CK techniques and operational details, as newer activity may introduce additional methods not captured yet.
No campaigns linked yet.
No observed data linked yet.
56
Techniques
48
Tools
0
Campaigns
86
IOCs
0
Observed Data
11
Tactics