logo

Lazarus Group’s ‘Graphalgo’ Fake Recruiter Campaign Targets GitHub, npm, and PyPI to Spread Malware

ID: a44575fb-bfb5-5bb2-b6cf-cf563243253e

STIX ID: report--a44575fb-bfb5-5bb2-b6cf-cf563243253e

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-02-12

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

ReversingLabs links a Lazarus Group operation called "graphalgo" to a developer‑targeted software supply‑chain campaign that used fake recruiter postings and a fabricated company (Veltrix Capital) to distribute malicious npm/PyPI packages (notably bigmathutils and graphnetworkx). The packages acted as first‑stage loaders that fetched a RAT with token‑protected C2, capable of file transfers, command execution, and checks for MetaMask—indicating a focused effort to compromise crypto developers and steal assets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.