logo

Malicious npm and PyPI packages linked to Lazarus APT fake recruiter campaign

ID: 152b2346-d82c-5763-bd4c-89273cde4405

STIX ID: report--152b2346-d82c-5763-bd4c-89273cde4405

Feed Name: Security Affairs

Threat Score
88/100

Date Published: 2026-02-15

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

ReversingLabs uncovered a modular, multi-stage supply-chain campaign dubbed "graphalgo" that uses fake blockchain recruiters and interview coding tasks to get developers to install malicious npm and PyPI packages; these packages, some of which achieved significant downloads, deliver a RAT capable of file access, command execution, and crypto-wallet checks. The report links the operation to North Korea’s Lazarus Group based on recurring patterns (fake interviews, crypto lures, delayed malicious updates, token-protected C2, GMT+9 timestamps) and warns the campaign remains active and evolving across GitHub, npm, and PyPI.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.