Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

A threat actor tracked as JINX-0164 is running an active campaign against cryptocurrency firms and software developers, combining fake LinkedIn recruiter outreach with a confirmed supply chain compromise of the npm package @velora-dex/sdk. Developers who installed the malicious package received persistent macOS malware capable of stealing credentials, SSH keys, cryptocurrency wallet data, and messaging platform sessions, while also granting the attacker remote access and CI/CD pipeline infiltration. Organizations in the cryptocurrency and DeFi sectors that employ macOS developers or depend on npm-distributed packages face immediate risk of credential theft, source code poisoning, and cascading compromise across their development infrastructure.

Author

Tech Jacks Solutions