logo

Fake recruiter campaign targets crypto devs

ID: b8d0993f-9f8b-57b4-b83d-ef3b5f38a33e

STIX ID: report--b8d0993f-9f8b-57b4-b83d-ef3b5f38a33e

Feed Name: ReversingLabs Blog

Threat Score
90/100

Date Published: 2026-02-11

Date Updated: 2026-04-29

Author: Karlo Zanki

...
...

ReversingLabs describes the graphalgo supply-chain campaign attributed to North Korea’s Lazarus Group that lures JavaScript and Python developers with fake recruiter job tasks and malicious GitHub/npm/PyPI dependencies; the campaign uses modular fake companies and repositories to distribute downloader packages which fetch a token-protected RAT (with Metamask checks) from C2 infrastructure (e.g., codepool.cloud), has amassed substantial downloads (e.g., bigmathutils >10K), and includes multiple IoCs and cross-language payloads indicating a high-sophistication, ongoing APT operation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.