North Korea-linked Lazarus Group has been tied to an expanded “fake recruiter” operation targeting cryptocurrency-sector Python and JavaScript developers by luring them with job offers and coding assessments that require installing trojanized dependencies from npm and PyPI. ReversingLabs reports the activity has been ongoing since May 2025 and uses a multi-stage, modular infection chain that hides malicious functionality behind layers of indirection across public services such as GitHub, npm, and PyPI, helping the operation persist even as individual components are removed.
The campaign (codenamed Graphalgo) reportedly uses a “bait-and-switch” approach in which initially benign packages build trust and download volume before later versions introduce malicious payloads; one highlighted npm package, bigmathutils, exceeded 10,000 downloads prior to the malicious update. Reported package names associated with the operation include npm packages such as graphalgo, graphlibcore, and bigmathutils, and PyPI packages such as graphalgo, graphlibx, and bigmathutils; the threat actors also create supporting legitimacy artifacts (e.g., a purported crypto firm like Veltrix Capital, related domains, and GitHub organizations/repositories) to make the recruitment workflow appear authentic and to deliver the compromised projects used in “assessments.”

Trace attribution and downstream blast radius.
10 events from the most recent confirmed update back to the earliest known activity.
Sophos Counter Threat Unit reported that the North Korean group Nickel Alley targeted freelance and high-value software developers through fake interviews on LinkedIn, Upwork, and Fiverr, using fraudulent company pages, GitHub repositories, and malicious or typosquatted npm packages. The campaign used ClickFix-style lures and npm-based execution to deploy PyLangGhost RAT, with Sophos noting earlier use of a GoLangGhost variant and warning the activity could support cryptocurrency theft, supply-chain compromise, or espionage.
A ReversingLabs publication referenced on 2026-04-09 said the Lazarus-linked Graphalgo fake recruiter-test campaign had re-emerged. This indicates the operation was still active or had resumed in a new wave after its earlier public disclosure.
An April 2026 investigation uncovered a malicious npm dependency chain tied to the GitHub organizations Mentonex and FluxMarketX, including packages such as logkitx, logger-base, and dev-log-core that delivered a backdoor via Vercel-hosted infrastructure. The report also mapped multiple fake developer personas and facilitator recruitment activity across GitHub, LinkedIn, dev.to, freelance sites, and job boards, assessing the cluster as closely aligned with North Korean tradecraft.
Reporting also highlighted an npm-based extortion scheme dubbed "XPACK ATTACK," in which package installs were blocked with an HTTP 402-style paywall demanding 0.1 USDC or ETH. The campaign additionally collected GitHub usernames and device fingerprints from affected users.
Separately from Graphalgo, JFrog reported that the npm package "duer-js" delivered the "Bada Stealer" malware, which stole browser and Discord data, exfiltrated it via Discord webhook and Gofile, and downloaded a secondary payload for Discord persistence. This was disclosed alongside broader reporting on malicious package abuse in the npm ecosystem.
In February 2026, ReversingLabs disclosed the "graphalgo" operation and attributed it to Lazarus with medium-to-high confidence based on tradecraft overlap, crypto targeting, token-based C2 similarities to prior activity, and GMT+9 commit-time artifacts. The report said the campaign remained active with no signs of stopping.
Developers who executed the trojanized coding projects pulled malicious dependencies from npm or PyPI that ultimately installed a remote access trojan. The malware supported system and process discovery, command execution, file access and exfiltration, additional payload delivery, and checked for MetaMask, indicating likely cryptocurrency theft objectives.
One npm package, "bigmathutils," was reportedly first distributed as a benign package and accumulated more than 10,000 downloads before a later bait-and-switch update introduced a malicious payload, including version 1.1.0. This reflected the campaign's tactic of delaying malicious updates to evade detection and build victim trust.
As the campaign unfolded, the threat actor set up fake company fronts such as Veltrix Capital, used LinkedIn, Facebook, Reddit, and GitHub to approach candidates, and published malicious packages to npm and PyPI. Researchers identified 192 malicious packages used as part of the multi-stage infection chain.
ReversingLabs assessed the North Korea-linked Lazarus Group's recruitment-themed supply-chain campaign, later dubbed "graphalgo," as active since early May 2025. The operation targeted JavaScript and Python developers, especially in crypto and Web3, through fake recruiter outreach and coding challenges.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 20 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
10 references tracked. Mallory keeps watching after this page renders.
itpro.com
Open sourcebsky.app
Open sourcenkinternet.com
Open sourcesecurityaffairs.com
Open sourcesecurityonline.info
Open sourcebleepingcomputer.com
Open sourcevulnu.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.