Skip to content
Lazarus Group’s ‘Graphalgo’ Fake Recruiter Campaign Exploits GitHub, npm, and PyPI to Distribute Malware

Lazarus Group’s ‘Graphalgo’ Fake Recruiter Campaign Exploits GitHub, npm, and PyPI to Distribute Malware

Cybersecuritynews •Tushar Subhra Dutta • February 12, 2026

The North Korean state- hacking team, Lazarus Group, has launched a sophisticated fake recruiter campaign targeting cryptocurrency developers through a malicious operation called “graphalgo.” Active since May 2025, this coordinated attack uses fraudulent job offers to distribute remote access trojans to unsuspecting developers working with blockchain and cryptocurrency technologies. The campaign exploits trusted open-source package […]

Extracted Entities

APT Groups (1)

Attack Types (2)

Campaigns (1)

Platforms (2)

Tools (1)