• bitcoinBitcoin (BTC) $ 63,788.00
  • ethereumEthereum (ETH) $ 1,673.21
  • tetherTether (USDT) $ 0.999506
  • bnbBNB (BNB) $ 605.17
  • usd-coinUSDC (USDC) $ 0.999844
  • xrpXRP (XRP) $ 1.14
  • solanaSolana (SOL) $ 67.36
  • tronTRON (TRX) $ 0.315293
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • dogecoinDogecoin (DOGE) $ 0.086608
  • hyperliquidHyperliquid (HYPE) $ 59.28
  • usdsUSDS (USDS) $ 0.999716
  • leo-tokenLEO Token (LEO) $ 9.61
  • rainRain (RAIN) $ 0.013060
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • zcashZcash (ZEC) $ 417.39
  • moneroMonero (XMR) $ 342.64
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • cardanoCardano (ADA) $ 0.172666
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • stellarStellar (XLM) $ 0.187956
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • canton-networkCanton (CC) $ 0.162900
  • whitebitWhiteBIT Coin (WBT) $ 52.03
  • chainlinkChainlink (LINK) $ 7.93
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • the-open-networkToncoin (TON) $ 1.69
  • ethena-usdeEthena USDe (USDE) $ 0.999549
  • susdssUSDS (SUSDS) $ 1.08
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • daiDai (DAI) $ 0.999964
  • bitcoin-cashBitcoin Cash (BCH) $ 203.82
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • memecoreMemeCore (M) $ 3.03
  • hedera-hashgraphHedera (HBAR) $ 0.078170
  • litecoinLitecoin (LTC) $ 43.44
  • wethWETH (WETH) $ 2,268.37
  • labLAB (LAB) $ 9.88
  • suiSui (SUI) $ 0.755900
  • hashnote-usycCircle USYC (USYC) $ 1.13
  • usdt0USDT0 (USDT0) $ 0.998824
  • shiba-inuShiba Inu (SHIB) $ 0.000005
  • avalanche-2Avalanche (AVAX) $ 6.62
  • paypal-usdPayPal USD (PYUSD) $ 0.999870
  • crypto-com-chainCronos (CRO) $ 0.059308
  • global-dollarGlobal Dollar (USDG) $ 0.999968
  • nearNEAR Protocol (NEAR) $ 2.01
  • tether-goldTether Gold (XAUT) $ 4,201.27
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • audieraAudiera (BEAT) $ 7.62
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.14
  • bittensorBittensor (TAO) $ 214.62
  • pax-goldPAX Gold (PAXG) $ 4,209.63
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.058920
  • mantleMantle (MNT) $ 0.539149
  • ondo-financeOndo (ONDO) $ 0.358526
  • aster-2Aster (ASTER) $ 0.631838
  • ripple-usdRipple USD (RLUSD) $ 1.00
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • polkadotPolkadot (DOT) $ 0.968568
  • worldcoin-wldWorldcoin (WLD) $ 0.479139
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • uniswapUniswap (UNI) $ 2.50
  • okbOKB (OKB) $ 74.07
  • htx-daoHTX DAO (HTX) $ 0.000002
  • falcon-financeFalcon USD (USDF) $ 0.995817
  • pi-networkPi Network (PI) $ 0.127062
  • usddUSDD (USDD) $ 0.999641
  • bfusdBFUSD (BFUSD) $ 0.999420
  • skySky (SKY) $ 0.056396
  • internet-computerInternet Computer (ICP) $ 2.36
  • morphoMorpho (MORPHO) $ 1.99
  • bitget-tokenBitget Token (BGB) $ 1.80
  • pepePepe (PEPE) $ 0.000003
  • ethereum-classicEthereum Classic (ETC) $ 7.19
  • cosmosCosmos Hub (ATOM) $ 2.01
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • united-stablesUnited Stables (U) $ 1.00
  • aaveAave (AAVE) $ 64.82
  • blockchain-capitalBlockchain Capital (BCAP) $ 106.96
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.22
  • quant-networkQuant (QNT) $ 66.45
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • superstate-short-duration-us-government-securities-fund-ustbInvesco Short Duration US Government Securities Fund (USTB) $ 11.11
  • usdtbUSDtb (USDTB) $ 0.999936
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • kucoin-sharesKuCoin (KCS) $ 6.72
  • dexeDeXe (DEXE) $ 19.08
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • render-tokenRender (RENDER) $ 1.69
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.11
  • kaspaKaspa (KAS) $ 0.031060
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • stable-2​​Stable (STABLE) $ 0.035826
  • nexoNEXO (NEXO) $ 0.801025
  • wbnbWrapped BNB (WBNB) $ 759.61
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.074580
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • algorandAlgorand (ALGO) $ 0.087021
  • ethenaEthena (ENA) $ 0.078333
  • gatechain-tokenGate (GT) $ 6.57
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.690685
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.04
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • venice-tokenVenice Token (VVV) $ 14.62
  • flare-networksFlare (FLR) $ 0.007911
  • justJUST (JST) $ 0.076095
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • xdce-crowd-saleXDC Network (XDC) $ 0.030477
  • filecoinFilecoin (FIL) $ 0.763158
  • ghoGHO (GHO) $ 0.998971
  • beldexBeldex (BDX) $ 0.076305
  • midnight-3Midnight (NIGHT) $ 0.034911
  • jupiter-exchange-solanaJupiter (JUP) $ 0.169226
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • usual-usdUsual USD (USD0) $ 0.998660
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • yldsYLDS (YLDS) $ 0.999802
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • hash-2Provenance Blockchain (HASH) $ 0.010086
  • official-trumpOfficial Trump (TRUMP) $ 2.30
  • aptosAptos (APT) $ 0.651912
  • clbtcclBTC (CLBTC) $ 76,920.00
  • pump-funPump.fun (PUMP) $ 0.001526
  • arbitrumArbitrum (ARB) $ 0.084675
  • a7a5A7A5 (A7A5) $ 0.013214
  • spiko-amundi-overnight-swap-fund-eurSpiko Amundi Overnight Swap Fund (EUR) (EURSAFO) $ 1.16
  • injective-protocolInjective (INJ) $ 5.14
  • usxUSX (USX) $ 0.999453
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • true-usdTrueUSD (TUSD) $ 0.998821
  • ousgOndo Short-Term U.S. Government Bond Fund (OUSG) $ 115.55
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • adi-tokenADI (ADI) $ 3.73
  • tbtctBTC (TBTC) $ 70,942.00
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.32
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • kite-2Kite (KITE) $ 0.192285
  • dashDash (DASH) $ 34.72
  • euro-coinEURC (EURC) $ 1.16
  • vechainVeChain (VET) $ 0.005069
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.188607
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.006784
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000074
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • hastra-primePRIME (PRIME) $ 1.04
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.616719
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • apxusdapxUSD (APXUSD) $ 0.962345
  • humanityHumanity (H) $ 0.221832
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • cocaCOCA (COCA) $ 1.30
  • bonkBonk (BONK) $ 0.000004
  • ethgas-2ETHGas (GWEI) $ 0.183778
  • lighterLighter (LIT) $ 1.53
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • curve-dao-tokenCurve DAO (CRV) $ 0.241080
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • the9bitThe9bit (9BIT) $ 0.043577
  • sei-networkSei (SEI) $ 0.052911
  • aerodrome-financeAerodrome Finance (AERO) $ 0.358992
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997798
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • siren-2Siren (SIREN) $ 0.444542
  • blockstackStacks (STX) $ 0.180825
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • kinesis-goldKinesis Gold (KAU) $ 139.54
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • unibaseUnibase (UB) $ 0.129806
  • sun-tokenSun Token (SUN) $ 0.016913
  • celestiaCelestia (TIA) $ 0.327953
  • pyth-networkPyth Network (PYTH) $ 0.038419
  • spx6900SPX6900 (SPX) $ 0.321110
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • skyaiSkyAI (SKYAI) $ 0.291234
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • usdgoUSDGO (USDGO) $ 0.999782
  • ether-fiEther.fi (ETHFI) $ 0.316338
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • gnosisGnosis (GNO) $ 105.01
  • chilizChiliz (CHZ) $ 0.026134
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • jito-governance-tokenJito (JTO) $ 0.548050
  • apenftAINFT (NFT) $ 0.00000027
  • kinesis-silverKinesis Silver (KAG) $ 69.39
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • bittorrentBitTorrent (BTT) $ 0.00000027
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • tezosTezos (XTZ) $ 0.236032
  • monadMonad (MON) $ 0.021234
  • royal-dollarRoyal Dollar (RUSD) $ 1.00
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • zebec-networkZebec Network (ZBCN) $ 0.002548

Hackers Use Fake LinkedIn Jobs to Steal Crypto Developer Code Pipelines

0 1


A previously undocumented threat actor is systematically targeting cryptocurrency developers through fake LinkedIn recruitment campaigns, installing custom malware on their computers and then using that access to compromise the company’s entire software development infrastructure.

Security firm Wiz has named the group JINX-0164 and has been tracking it since at least mid-2025. The group has conducted multiple successful intrusions against cryptocurrency organisations, in at least one case attempting a full supply chain attack by distributing malicious code through a widely used public package.

How the Attack Works

The attack follows a consistent pattern across every documented case:

  • A credible LinkedIn profile reaches out with a job opportunity or business proposal
  • The target is invited to a virtual meeting through what appears to be Microsoft Teams or a similar platform
  • The meeting link leads to a fake domain where a malicious file is downloaded under the guise of fixing an audio or technical problem
  • The file installs AUDIOFIX, a custom Python-based malware with full remote access capabilities
  • Attackers harvest passwords, SSH keys, browser credentials, cryptocurrency wallet extensions, AWS and cloud API keys, and active sessions from Discord, Slack, and Telegram
  • GitHub tokens extracted from the compromised machine are used to access internal code repositories
  • Malicious code is injected directly into the development pipeline, infecting every other developer who pulls from those repositories

The entire process from initial LinkedIn contact to full pipeline compromise took two weeks in one documented case.

The Supply Chain Attack

On April 7, 2026, JINX-0164 trojanised version 9.4.1 of the npm package @velora-dex/sdk, a widely used cryptocurrency SDK. Three lines of malicious code were appended to the package that silently downloaded a lightweight backdoor called MINIRAT whenever the package was imported by any developer.

The attack targeted npm credentials rather than the GitHub source code, meaning the repository appeared clean while the published package was compromised.

Related: FIFA World Cup 2026 Turns Into Crypto Prediction Battleground

Why Developers Are the Target

Developer machines hold credentials for every system the developer touches. Cloud infrastructure, code repositories, package managers, internal APIs. JINX-0164 showed almost no interest in traditional cloud resources after gaining access. Their focus was exclusively on code distribution systems and development infrastructure, the most efficient path to reaching thousands of end users through a single trusted package.

What to Watch For

Wiz identified several indicators that helped detect the attack including unverified commit badges on GitHub’s Vigilant Mode, mismatches between GPG key history and commit authors, and git push activities traced back to a single compromised endpoint through audit logs.

The group routes all activity through Mullvad, Astrill, and ExpressVPN to mask their origin. While no definitive attribution has been confirmed, Wiz noted tactical similarities to North Korean threat groups including UNC1069 and Sapphire Sleet, though no infrastructure overlap with known groups has been identified.

Related: Michael Saylor Outlines the Four Bitcoin Ideologies



Source link

Leave A Reply

Your email address will not be published.