Malicious npm and PyPI packages linked to Lazarus APT fake recruiter campaign

5 Min Read

Researchers found malicious npm and PyPI packages tied to a fake recruitment campaign linked to North Korea’s Lazarus Group.

ReversingLabs researcher uncovered new malicious packages on npm and PyPI connected to a fake job recruitment campaign attributed to the North Korea-linked Lazarus Group. The campaign uses deceptive hiring themes to trick developers into downloading infected packages, continuing the group’s efforts to target the software supply chain.

- Advertisement -

“The ReversingLabs research team has identified a new branch of a fake recruiter campaign conducted by the North Korean hacking team Lazarus Group.” reads the report published by ReversingLabs. “The campaign, which the team named graphalgo, based on the first package included in this campaign in the npm repository, has been active since the beginning of May 2025.”

The campaign, tracked as ‘graphalgo’, has been active since May 2025 and targets JavaScript and Python developers with fake cryptocurrency recruiter tasks. Attackers approach victims on LinkedIn, Facebook, and Reddit, posing as a blockchain company. Malicious code is hidden through multiple public platforms, including GitHub, npm, and PyPI. The researchers noticed that one npm package, bigmathutils, gained over 10,000 downloads before attackers pushed a malicious update.


What do you think? Post a comment.


The Graphalgo campaign is a modular, multi-stage operation designed to stay active even if parts are exposed:

- Advertisement -

EXPLORE MORE

Letters from 22 women documenting Rupnik’s abuse add to allegations

Previously undisclosed letters from 22 women alleging abuse by Father Marko Rupnik…

Wanted: Suspect for Assault in the 16th District [VIDEO]

The Philadelphia Police Department needs your help: The police are investigating an…

Phillies cough up six-run lead, get swept in Miami – Phillies Nation

Jesús Luzardo allowed six runs in 6 1/3 innings in a loss…

Russia Hits Kiev Ammo Dump Next To Homes; Ukraine Admits 90% Of Retail Food Logistics Wrecked

A Russian drone struck a Ukrainian Defense Forces ammunition storage site in…

Leaked Pentagon Document Reveals Senior Military Leaders Warning Defense Secretary Hegseth Over Unsustainable Iran War

WASHINGTON — High-level internal dissent within the Pentagon has spilled into the…

BENEATH THE UNBEATEN LEGEND: REEXAMINING THE KHABIB NURMAGOMEDOV MYTHOS

LAS VEGAS — For years, the story of Khabib Nurmagomedov has been…

Phase 1 – Fake company:
Attackers created a fake blockchain firm, Veltrix Capital, with websites and GitHub organizations that look legitimate but lack real leadership details. When one setup risks exposure, they spin up a new company, domains, and AI-generated content to rebuild trust.

Phase 2 – Interview tasks:
The fake company publishes GitHub “job interview” repositories in Python and JavaScript. These projects look harmless, but they secretly depend on malicious npm or PyPI packages. When candidates run the tasks, the malicious dependency executes on their systems.

Phase 3 – Recruiting:
Victims are lured through Reddit, Facebook groups, LinkedIn, and direct recruiter messages. Some recruiters appear real, adding credibility, but disengage when questioned about the company.

Malicious npm and PyPI packages linked to Lazarus APT fake recruiter campaign | Philly PI

Phase 4 – Malicious dependencies:
The backend relies on malicious open-source packages hosted on npm and PyPI. Early “graph-” packages impersonate popular libraries, while later “big-” packages build user trust first, then deliver malware in delayed updates.

Phase 5 – Final payload:
Infected systems download a RAT that supports file access, command execution, and process control. The malware uses token-protected C2 communication and checks for crypto wallets like MetaMask, pointing to financial theft motives.

Malicious npm and PyPI packages linked to Lazarus APT fake recruiter campaign | Philly PI

North Korean threat actors, widely linked to the Lazarus Group, have a long track record of abusing npm and PyPI. In 2023, researchers exposed the VMConnect campaign, where fake PyPI packages tied to sham GitHub repos delivered malware. A year later, the operation evolved into fake recruiter coding tests: victims ran malicious packages disguised as interview tasks, triggering second-stage downloads. Reports from other cybersecurity firms, including Phylum, Unit 42, Veracode, and Socket, documented similar npm campaigns.

Attribution to Lazarus is based on repeated patterns: fake job interviews, crypto-focused lures, multistage encrypted malware, delayed malicious updates, token-protected C2, and GMT+9 timestamps. The campaign’s modular design allows attackers to swap fake “frontends” while reusing backend infrastructure. With new package waves and payload variants still emerging, the operation appears ongoing and highly sophisticated.

“Evidence suggests that this is a highly sophisticated campaign. Its modularity, long-lived nature, patience in building trust across different campaign elements, and the complexity of the multilayered and encrypted malware point to the work of a state-sponsored threat actor.” concludes the report. “Fake interviews as the initial contact vector, as well as a cryptocurrency-focused story and malware, together with other techniques mentioned in this blog post, point to North Korea’s Lazarus Group. “

Pierluigi Paganini



Share This Article

Resurfaced Childhood Photo of Hasan Piker Triggers Online Debate Over Wealth and Authenticity

An old photograph of political commentator and Twitch streamer…

Inside Abby Hornacek’s World: The FOX Nation Host on Adventure, Family, and Chasing Her Passions

Whether she’s sandboarding down massive dunes, touring iconic sports…

Architect of Empire, Harbinger of Famine: The Legacy of Sir Charles Trevelyan

Sir Charles Edward Trevelyan, 1st Baronet (1807–1886) stands as…

Colombia declares emergency after devastating earthquake (VIDEOS)

At least 169 people have been killed and 668…

Oscar-winner rock star accused of flagrant sexual misconduct

American actor and Thirty Seconds to Mars frontman Jared…

CIA Director Pushed Trump-Putin-Zelensky Summit During Moscow Visit: Report

Yet another take has been issued, and more alleged…

Hollywood’s Quiet Powerhouse: How Frances Fisher Built a Five-Decade Legacy

Few character actresses command the screen with the aristocratic…

Cops Raid Home of Rep. Ilhan Omar’s Son, Seizing Firearms and Ammunition

MINNEAPOLIS — Police executed a search warrant at a…

US and Israel likely behind Ceuta crisis

The mass crossing may have been a test of…

CONVERSATION

Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted