Malicious npm and PyPI packages linked to Lazarus APT fake recruiter campaign
ID: 152b2346-d82c-5763-bd4c-89273cde4405
STIX ID: report--152b2346-d82c-5763-bd4c-89273cde4405
Feed Name: Security Affairs
ReversingLabs uncovered a modular, multi-stage supply-chain campaign dubbed "graphalgo" that uses fake blockchain recruiters and interview coding tasks to get developers to install malicious npm and PyPI packages; these packages, some of which achieved significant downloads, deliver a RAT capable of file access, command execution, and crypto-wallet checks. The report links the operation to North Korea’s Lazarus Group based on recurring patterns (fake interviews, crypto lures, delayed malicious updates, token-protected C2, GMT+9 timestamps) and warns the campaign remains active and evolving across GitHub, npm, and PyPI.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
