Lazarus Group’s ‘Graphalgo’ Fake Recruiter Campaign Targets GitHub, npm, and PyPI to Spread Malware
ID: a44575fb-bfb5-5bb2-b6cf-cf563243253e
STIX ID: report--a44575fb-bfb5-5bb2-b6cf-cf563243253e
Feed Name: GBHackers
ReversingLabs links a Lazarus Group operation called "graphalgo" to a developer‑targeted software supply‑chain campaign that used fake recruiter postings and a fabricated company (Veltrix Capital) to distribute malicious npm/PyPI packages (notably bigmathutils and graphnetworkx). The packages acted as first‑stage loaders that fetched a RAT with token‑protected C2, capable of file transfers, command execution, and checks for MetaMask—indicating a focused effort to compromise crypto developers and steal assets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
