Lazarus Group 'Graphalgo' Fake-Recruiter npm/PyPI Campaign
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·3dWs3v…N99qSummary
The 'graphalgo' campaign is a North Korean state-sponsored software supply-chain operation attributed to the Lazarus Group, active since at least May 2025 and publicly disclosed in February 2026. Threat actors impersonate cryptocurrency-sector recruiters using fabricated companies — most notably 'Veltrix Capital' — to deliver coding-assessment repositories seeded with malicious npm and PyPI packages that install a remote-access trojan (RAT) targeting developer systems and cryptocurrency wallets. By April 2026 the campaign had respawned under new personas including 'Blockmerce' and 'Bridgers Finance', with operatives registering a real U.S. LLC to enhance credibility.
Connected Entities
1 entities · 10 linked investigations- + 3 more
Timeline(13 events)
4 April 2025
Domain veltrixcap[.]org registered, establishing fake Veltrix Capital infrastructure.
ReversingLabs — Inside the 'graphalgo' campaign2 May 2025
First malicious npm package, graphalgo version 2.2.6, published to the npm registry.
ReversingLabs — Inside the 'graphalgo' campaignMay 2025
Alleged start of recruitment outreach via LinkedIn, Facebook, and Reddit under Veltrix Capital persona.
The Hacker News13 June 2025
First malicious PyPI package, graphalgo, published to the Python Package Index.
ReversingLabs — Inside the 'graphalgo' campaignAugust 2025
Blocmerce LLC registered as a real Florida LLC with fake CEO 'Alexandre Miller', pre-positioning for the campaign's next persona phase.
HackRead — GraphAlgo Scam: Lazarus Hackers Register Real US LLCs21 September 2025
Backup domain veltrixcapital[.]ai registered.
ReversingLabs — Fake recruiter campaign targets crypto developers with RAT17 November 2025
'Big'-prefixed npm package wave begins, starting with bignumx and bignum.
ReversingLabs — Inside the 'graphalgo' campaign9 December 2025
'Big'-prefixed PyPI package wave begins.
ReversingLabs — Inside the 'graphalgo' campaign2026
bigmathutils accumulates over 4,200 weekly downloads; no malicious payload present in published versions yet.
ReversingLabs — Inside the 'graphalgo' campaign4 February 2026
VBS payload variant identified by researchers.
ReversingLabs — Fake recruiter campaign targets crypto developers with RAT11 February 2026
Malicious bigmathutils version 1.1.0 published; package had exceeded 10,000 cumulative downloads. Malicious version subsequently removed and package marked deprecated.
ReversingLabs — Fake recruiter campaign targets crypto developers with RAT15 February 2026
ReversingLabs publicly discloses the graphalgo campaign; widespread coverage by The Hacker News, Security Affairs, GBHackers, SC Media, and others.
Security AffairsApril 2026
ReversingLabs documents campaign respawn under Blockmerce and Bridgers Finance personas, with new C2 domain huvaret[.]art and shift to GitHub release artifact delivery.
ReversingLabs — Graphalgo campaign respawnedDecision Log
- hash: 9a1421oJxS59yRbJSVBMtGNBN597D8CmSwUFzAfUDD7i
- hash: 9to4VitfoBgtWJBAoDijRhT7zMkPvfnhf4ytpxcyZvkb
- hash: 2eqqBHujYKL3gGS4JjNip7SqejcNnCPJK8eo9BGNw2Z9
This investigation is cryptographically anchored to the Solana blockchain (3 events). 16 of 17 cited source URLs have an Internet Archive snapshot.
model: claude-code-investigator
generated: 6/8/2026, 1:21:52 AM
last updated: 7/27/2026, 5:00:40 PM
3 viewsavoid.net — verified advice for a post-truth world