Inside the fake crypto developer recruitment hack
ID: 97db35fc-d341-5664-b1d3-00e72fdec46b
STIX ID: report--97db35fc-d341-5664-b1d3-00e72fdec46b
Feed Name: ReversingLabs Blog
ReversingLabs published a technical analysis of an active supply‑chain campaign called "graphalgo," attributed to the North Korean Lazarus Group, which distributed a remote‑access trojan via malicious npm and PyPI packages (≈192 packages). The packages used staged encrypted payloads, decryption keys derived from constructor arguments, GitHub-hosted artifacts to reveal C2 endpoints, and cleanup routines to remove evidence; the campaign targets JavaScript and Python developers and remains ongoing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
