Graphalgo is a recruitment-themed software supply-chain malware campaign and remote-access trojan ecosystem attributed with medium-to-high confidence to the North Korea-linked Lazarus Group. It targets JavaScript, Python, Go, and DevOps practitioners, particularly those working in blockchain and cryptocurrency sectors. Operators use fake recruiter personas, fraudulent companies, job advertisements, and coding assessments to induce candidates to run projects that install malicious dependencies from public package registries. Malicious packages have also been distributed through Go modules and typosquatted Terraform providers. The payloads deploy remote-access trojans capable of collecting host and system information, enumerating processes, files, and directories, executing arbitrary commands and additional code, manipulating files, and uploading or downloading data. Graphalgo checks for cryptocurrency-wallet browser extensions, consistent with a financial-theft objective. Go variants use encrypted dual command-and-control channels involving Slack and blockchain-based dead drops, with per-victim cryptographic key material; they can execute Go or JavaScript code and remove themselves on command. Observed infections include Windows, Linux, and macOS systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
North Korea’s Lazarus Group has maintained a sustained presence in PyPI and npm targeting AI and developer tool packages under the campaign codenamed “Graphalgo.”
The coordinated campaign has been codenamed graphalgo in reference to the first package published in the npm registry... The packages ultimately act as a conduit to deploy a remote access trojan (RAT) that periodically fetches and executes commands from an external server.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Instead of direct attachments, attackers embed malicious dependencies inside packages on popular developer registries — npm and PyPI. When candidates run or debug the code as part of the “interview exercise,” these hidden packages install a remote access trojan (RAT) on their machine.
Instead of direct attachments, attackers embed malicious dependencies inside packages on popular developer registries — npm and PyPI. When candidates run or debug the code as part of the “interview exercise,” these hidden packages install a remote access trojan (RAT) on their machine.
The SHA256 hash is used as an AES key to decrypt a file path from within the package. The malware unzips the archive contents, AES decrypts each contained file.
kreuzwenker/docker [is] a typosquat of the popular kreuzwerker/docker Terraform provider.
“The malicious functionality is hidden using several layers of indirection across public services which include GitHub, npm and PyPI…”
For blockchain-based C2, the malware retrieves data from an Ethereum smart contract on the Arbitrum Sepolia testnet ... [and] reads encrypted commands from serviceData1 and serviceData2.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A targeted, multi-stage supply-chain malware family distributed through malicious NPM packages, Go modules, and Terraform providers. Its Go variant conditionally decrypts and launches a second-stage Go RAT, fingerprints the host, reports via Slack, and receives encrypted commands through Slack and an Ethereum/Arbitrum Sepolia blockchain dead drop. Commands can execute additional Go or JavaScript code or self-delete.
A Lazarus-linked fake recruiter/software supply chain campaign using malicious npm and PyPI dependencies embedded in “job interview” GitHub projects. When executed, the dependencies run a multi-stage, modular infection chain that ultimately downloads a RAT with file access, command execution, and process control; it also checks for crypto wallets (e.g., MetaMask) and uses token-protected C2.
Post navigation Previous: Dream Job or Nightmare? Lazarus Group Hunts Crypto Devs with “Graphalgo” Malware
“Dream Job or Nightmare? Lazarus Group Hunts Crypto Devs with ‘Graphalgo’ Malware”
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.