logo

Inside the fake crypto developer recruitment hack

ID: 97db35fc-d341-5664-b1d3-00e72fdec46b

STIX ID: report--97db35fc-d341-5664-b1d3-00e72fdec46b

Feed Name: ReversingLabs Blog

Threat Score
90/100

Date Published: 2026-02-12

Date Updated: 2026-04-29

Author: Lucija Valentić

...
...

ReversingLabs published a technical analysis of an active supply‑chain campaign called "graphalgo," attributed to the North Korean Lazarus Group, which distributed a remote‑access trojan via malicious npm and PyPI packages (≈192 packages). The packages used staged encrypted payloads, decryption keys derived from constructor arguments, GitHub-hosted artifacts to reveal C2 endpoints, and cleanup routines to remove evidence; the campaign targets JavaScript and Python developers and remains ongoing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.