Lazarus Group’s ‘Graphalgo’ Fake Recruiter Campaign Exploits GitHub, npm, and PyPI to Distribute Malware
The North Korean hacking group, Lazarus Group, has initiated a fake recruiter campaign named "graphalgo" aimed at cryptocurrency developers. This campaign, active since May 2025, distributes remote access trojans through fraudulent job offers to…
The North Korean hacking group, Lazarus Group, has initiated a fake recruiter campaign named "graphalgo" aimed at cryptocurrency developers. This campaign, active since May 2025, distributes remote access trojans through fraudulent job offers to developers engaged with blockchain and cryptocurrency technologies.
The operation exploits open-source package repositories such as GitHub, npm, and PyPI, turning them into vectors for malware distribution. Attackers connect with potential victims via professional networking platforms and forums, presenting employment opportunities at fictitious companies primarily in the blockchain and cryptocurrency sectors.
The deceptive process involves providing victims with seemingly legitimate coding tests containing malicious dependencies designed to compromise systems. This campaign's modular architecture enables continued operation even when certain components are exposed.
The North Korean hacking group, Lazarus Group, has initiated a fake recruiter campaign named "graphalgo" aimed at cryptocurrency developers.
Infection Mechanism and Multi-Stage Payload Delivery
The infection begins when developers receive coding tasks from GitHub repositories managed by the fake companies. These tasks include dependencies linked to compromised packages on npm and PyPI. Upon execution, these dependencies trigger the installation of obfuscated payloads that download additional malware from command-and-control servers.
The final payload is a remote access trojan (RAT) capable of executing commands, uploading files, and potentially targeting cryptocurrency wallets such as MetaMask. Three versions of the RAT have been identified, written in JavaScript, Python, and Visual Basic Script.
The campaign employs token-protected authentication for communication with control servers, hindering security analysis. Evidence such as GMT+9 timezone timestamps and a focus on cryptocurrency aligns with known North Korean threat actor patterns, supporting attribution to the Lazarus Group.
Based on reporting by Cyber Security News.
