Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Lazarus Group’s ‘Graphalgo’ Fake Recruiter Campaign Exploits GitHub, npm, and PyPI to Distribute Malware

The North Korean hacking group, Lazarus Group, has initiated a fake recruiter campaign named "graphalgo" aimed at cryptocurrency developers. This campaign, active since May 2025, distributes remote access trojans through fraudulent job offers to…

The North Korean hacking group, Lazarus Group, has initiated a fake recruiter campaign named "graphalgo" aimed at cryptocurrency developers. This campaign, active since May 2025, distributes remote access trojans through fraudulent job offers to developers engaged with blockchain and cryptocurrency technologies.

The operation exploits open-source package repositories such as GitHub, npm, and PyPI, turning them into vectors for malware distribution. Attackers connect with potential victims via professional networking platforms and forums, presenting employment opportunities at fictitious companies primarily in the blockchain and cryptocurrency sectors.

The deceptive process involves providing victims with seemingly legitimate coding tests containing malicious dependencies designed to compromise systems. This campaign's modular architecture enables continued operation even when certain components are exposed.

The North Korean hacking group, Lazarus Group, has initiated a fake recruiter campaign named "graphalgo" aimed at cryptocurrency developers.
Joseph Cain · Thehackingpost

Infection Mechanism and Multi-Stage Payload Delivery

The infection begins when developers receive coding tasks from GitHub repositories managed by the fake companies. These tasks include dependencies linked to compromised packages on npm and PyPI. Upon execution, these dependencies trigger the installation of obfuscated payloads that download additional malware from command-and-control servers.

The final payload is a remote access trojan (RAT) capable of executing commands, uploading files, and potentially targeting cryptocurrency wallets such as MetaMask. Three versions of the RAT have been identified, written in JavaScript, Python, and Visual Basic Script.

Advertisement

The campaign employs token-protected authentication for communication with control servers, hindering security analysis. Evidence such as GMT+9 timezone timestamps and a focus on cryptocurrency aligns with known North Korean threat actor patterns, supporting attribution to the Lazarus Group.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories