Researchers studying cybersecurity have found a new collection of harmful packages in npm and the Python Package Index (PyPI) repository that are connected to a phony recruitment effort that was planned by the Lazarus Group, which has ties to North Korea.
In honor of the first package to be uploaded in the npm registry, the coordinated campaign has been nicknamed graphalgo. It is estimated to have been operational from May 2025.
According to a report by Karlo Zanki, a researcher at ReversingLabs, developers are contacted through social media sites like Facebook and LinkedIn or through job postings on forums like Reddit. A well-planned narrative about a business engaged in blockchain and cryptocurrency exchanges is part of the campaign.
Interestingly, bigmathutils, one of the detected npm packages, received over 10,000 downloads following the publication of the first, non-malicious version and prior to the release read more about Lazarus Campaign Plants Malicious Packages in npm and PyPI Ecosystems.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
