FeedExploreAsk AIAlertsSavedProfile

Categories

AICybersecurityInfrastructureDatabaseTech Updates

Tech news that matters.

FeedExploreAskAlertsSavedProfile
Back to feed
Cybersecurity·High

New Malware Targets Crypto Developers

An illustration depicting a cyberattack, with a malware symbol on a computer screen targeting cryptocurrency.
Apple logo
Apple news →

TL;DR: A new threat actor is targeting cryptocurrency firms using fake recruiter messages and custom macOS malware. The campaign uses sophisticated social engineering to trick employees, aiming to steal digital assets by compromising CI/CD infrastructure. This highlights a growing risk for developers and security teams in the crypto space.

By Neeraj Dhiman·3h ago·1 min read·updated 1h ago
Source

Key facts

Category
Cybersecurity
Impact
High
Published
3h ago
Source
The Hacker News

Full summary

A new threat actor is using fake recruiter lures and custom macOS malware to steal digital assets from cryptocurrency firms by targeting developers.

A previously unknown threat actor is running a new campaign against cryptocurrency companies. The attack begins with social engineering, where hackers pose as recruiters to lure employees, particularly developers. They use custom-built malware designed specifically for macOS to gain access to company systems and facilitate the theft of digital assets. The operation, tracked as JINX-0164, is highly sophisticated, using tailored approaches to build trust with targets before deploying the malicious software, making the initial contact seem legitimate and difficult to detect.

This campaign is significant because it combines several advanced techniques: custom malware for macOS, targeted social engineering, and a focus on a high-value industry. The specific targeting of CI/CD (Continuous Integration/Continuous Deployment) infrastructure is particularly alarming for tech companies. Compromising this part of the development pipeline could allow attackers to inject malicious code, steal sensitive credentials, or disrupt operations, leading to significant financial and reputational damage. This threat highlights the need for heightened security awareness, especially among developers and engineers who hold privileged access to critical systems.

Action checklist

  1. 1Remind teams about social engineering risks, especially from unsolicited job offers.
  2. 2Verify recruiter identities through official channels before engaging.
  3. 3Scrutinize any requests to download or run software during recruitment.
  4. 4Ensure macOS endpoint protection and detection tools are up-to-date.
  5. 5Review access controls and security for CI/CD pipelines.

Tags

#security#malware#ci/cd#macos#social engineering#cryptocurrency

Related on Notifire

  • ResearchKubernetes security
  • ResearchSupply-chain security
  • ResearchCritical CVEs of 2026

✦ Notifire newsletter

Get more Cybersecurity intelligence

Join engineers getting Notifire’s verified tech briefings — short, sourced, and free. No spam, unsubscribe anytime.

The day's most important tech briefings. No spam, unsubscribe anytime.

Related stories

Primary source: The Hacker News

Tech intelligence for engineering teams

Short, verified briefings on AI, cybersecurity, infrastructure, and data — with the analysis and action steps that matter. Every briefing is sourced, fact-checked, and bylined to a named editor.

[email protected]Story tips & corrections welcomeHow we report →

The Notifire briefing

Verified tech intelligence in your inbox — AI, security, infra, and data.

The day's most important tech briefings. No spam, unsubscribe anytime.

Sections

  • AI
  • Cybersecurity
  • Infrastructure
  • Database
  • Tech Updates
  • Web3 & Chains

Newsroom

  • About Notifire
  • Editorial team
  • Editorial standards
  • Methodology
  • AI disclosure
  • Corrections

Resources

  • Explore
  • Research hubs
  • Comparisons
  • Tech glossary
  • FAQ
  • Alerts & watchlists

Follow

  • RSS feed
© 2026 NotifirePrivacyTermsCorrections
An independent, AI-assisted publication. Built at </Alpheric>
IntelligenceLive panel
Live

Top trending

Last 24h

    Popular tags

    Add to watchlist

    +OpenAI+Claude+PostgreSQL+Kubernetes+Cloudflare+AWS+CVE Critical

    Notifire score

    0–100 priority signal — combines impact, freshness, trending velocity, and source credibility.

  1. Atom feed
  2. LinkedIn
  3. X / Twitter
  4. Facebook
  5. Instagram
  6. YouTube