Skip to main content
Sign in

Lazarus Group 'Graphalgo' Fake-Recruiter npm/PyPI Campaign

avoid.net/lazarus-group-graphalgo-fake-recruiter-npm-pypi-campaign0/100·92% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·3dWs3v…N99q

Summary

The 'graphalgo' campaign is a North Korean state-sponsored software supply-chain operation attributed to the Lazarus Group, active since at least May 2025 and publicly disclosed in February 2026. Threat actors impersonate cryptocurrency-sector recruiters using fabricated companies — most notably 'Veltrix Capital' — to deliver coding-assessment repositories seeded with malicious npm and PyPI packages that install a remote-access trojan (RAT) targeting developer systems and cryptocurrency wallets. By April 2026 the campaign had respawned under new personas including 'Blockmerce' and 'Bridgers Finance', with operatives registering a real U.S. LLC to enhance credibility.

Have evidence about Lazarus Group 'Graphalgo' Fake-Recruiter npm/PyPI Campaign?

Timeline(13 events)

4 April 2025

Domain veltrixcap[.]org registered, establishing fake Veltrix Capital infrastructure.

ReversingLabs — Inside the 'graphalgo' campaign

2 May 2025

First malicious npm package, graphalgo version 2.2.6, published to the npm registry.

ReversingLabs — Inside the 'graphalgo' campaign

May 2025

Alleged start of recruitment outreach via LinkedIn, Facebook, and Reddit under Veltrix Capital persona.

The Hacker News

13 June 2025

First malicious PyPI package, graphalgo, published to the Python Package Index.

ReversingLabs — Inside the 'graphalgo' campaign

August 2025

Blocmerce LLC registered as a real Florida LLC with fake CEO 'Alexandre Miller', pre-positioning for the campaign's next persona phase.

HackRead — GraphAlgo Scam: Lazarus Hackers Register Real US LLCs

21 September 2025

Backup domain veltrixcapital[.]ai registered.

ReversingLabs — Fake recruiter campaign targets crypto developers with RAT

17 November 2025

'Big'-prefixed npm package wave begins, starting with bignumx and bignum.

ReversingLabs — Inside the 'graphalgo' campaign

9 December 2025

'Big'-prefixed PyPI package wave begins.

ReversingLabs — Inside the 'graphalgo' campaign

2026

bigmathutils accumulates over 4,200 weekly downloads; no malicious payload present in published versions yet.

ReversingLabs — Inside the 'graphalgo' campaign

4 February 2026

VBS payload variant identified by researchers.

ReversingLabs — Fake recruiter campaign targets crypto developers with RAT

11 February 2026

Malicious bigmathutils version 1.1.0 published; package had exceeded 10,000 cumulative downloads. Malicious version subsequently removed and package marked deprecated.

ReversingLabs — Fake recruiter campaign targets crypto developers with RAT

15 February 2026

ReversingLabs publicly discloses the graphalgo campaign; widespread coverage by The Hacker News, Security Affairs, GBHackers, SC Media, and others.

Security Affairs

April 2026

ReversingLabs documents campaign respawn under Blockmerce and Bridgers Finance personas, with new C2 domain huvaret[.]art and shift to GitHub release artifact delivery.

ReversingLabs — Graphalgo campaign respawned
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (3 events). 16 of 17 cited source URLs have an Internet Archive snapshot.

model: claude-code-investigator

generated: 6/8/2026, 1:21:52 AM

last updated: 7/27/2026, 5:00:40 PM

3 views

avoid.net — verified advice for a post-truth world