logo

Graphalgo fake recruiter campaign returns

ID: 6874a359-49a5-50ea-9367-f37f0c3a0097

STIX ID: report--6874a359-49a5-50ea-9367-f37f0c3a0097

Feed Name: ReversingLabs Blog

Threat Score
85/100

Date Published: 2026-04-09

Date Updated: 2026-04-30

Author: Karlo Zanki

...
...

ReversingLabs researchers detail the 'graphalgo' campaign that uses fake job interviews and spoofed crypto companies to trick developers into running setup scripts that fetch malicious dependencies from typo-squatted GitHub release artifacts; the payload is a multi-stage downloader leading to a RAT. The report describes novel TTPs (moving malicious dependencies into package-lock.json, hosting malicious artifacts as GitHub releases, git history rewriting to fabricate contributor trust, and blockchain-based infection signaling), provides IOCs (eg. huvaret.art and Ethereum contract/address), and links the activity to North Korean state-sponsored actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.