HomeSecurityLazarus campaign plants malicious npm and PyPI packages

Lazarus campaign plants malicious npm and PyPI packages

Cybersecurity researchers have discovered a new series of malicious packages in the npm and Python Package Index (PyPI) repositories, linked to a fake recruitment campaign organized by the North Korean-linked Lazarus Group. The coordinated campaign has been codenamed graphalgo, referring to the first package published to the npm registry. It is estimated to have been active since May 2025.

See also: Lazarus hackers target drone manufacturers in Europe

Lazarus

“ Developers are approached through social platforms like LinkedIn and Facebook, or through job postings on forums like Reddit ,” ReversingLabs researcher Karlo Zanki said in a report.

“The campaign involves a well-organized story surrounding a company involved in blockchain and cryptocurrency exchanges.” Notably, one of the identified npm packages, bigmathutils, attracted more than 10,000 downloads after the first, non-malicious version was published and before the second version containing a malicious payload was released.

As with many jobs-focused campaigns conducted by North Korean threat actors, the attack chain begins with the creation of a fake company like Veltrix Capital in the blockchain and cryptocurrency trading space and then building the necessary digital presence to create the illusion of legitimacy.

This involves registering a domain and creating an associated GitHub organization to host multiple repositories for use in code reviews. The repositories have been found to contain Python and JavaScript-based projects. The idea behind creating these repositories is to trick candidates applying to their Reddit job postings and Facebook groups into running the projects on their computers, essentially installing the malicious dependency and triggering the infection.

See also: The rise of North Korean hackers: $2 billion in cryptocurrencies stolen

Lazarus campaign plants malicious npm and PyPI packages

In some cases, victims are contacted directly by seemingly legitimate recruiters on LinkedIn. The packages ultimately act as a conduit for the deployment of a remote access trojan (RAT) that periodically retrieves and executes commands from an external server. It supports various commands to collect system information, enumerate files and directories, log running processes, create folders, rename files, delete files, and upload/download files.

Interestingly, the command and control (C2) communication is protected by a token-based mechanism to ensure that only requests with a valid token are accepted. This approach was previously observed in 2023 campaigns associated with a North Korean hacking group called Jade Sleet, also known as TraderTraitor or UNC4899. Essentially, it works like this: packets send system data as part of a registration step to the C2 server, which responds with a token.

This token is then sent back to the C2 server on subsequent requests to verify that they come from an already registered infected system.

See also: Lazarus: Researchers monitored the activity of hackers

Lazarus campaign plants malicious npm and PyPI packages

The findings indicate that North Korean state-sponsored threat actors continue to poison open source ecosystems with malicious packages in hopes of stealing sensitive data and conducting financial theft, as evidenced by RAT checks to see if the MetaMask browser extension is installed on the computer.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS