Lazarus Group Targets Developers with Malicious npm and PyPI Packages
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
The Lazarus Group, linked to North Korea, has launched a campaign named graphalgo, which involves planting malicious packages in both the npm and PyPI ecosystems. This campaign has been active since May 2025 and targets developers by presenting fake job opportunities related to blockchain and cryptocurrency. Researchers from ReversingLabs discovered that the attack begins with the establishment of a fake company, Veltrix Capital, and the creation of a digital presence to lend credibility to the operation.
Developers are approached through social media platforms like LinkedIn and Facebook, as well as job postings on forums such as Reddit. The malicious packages, including bigmathutils, were downloaded over 10,000 times before the malicious versions were released. The packages serve as conduits for deploying a remote access trojan (RAT) that can execute various commands on infected systems.
The RAT can gather system information, manage files, and communicate with a command-and-control (C2) server using a token-based mechanism to authenticate requests. This sophisticated approach has been previously observed in campaigns linked to another North Korean hacking group, Jade Sleet. The findings indicate a high level of sophistication and patience in building trust with potential victims.
In addition to the graphalgo campaign, another malicious npm package called duer-js was discovered, which masquerades as a utility to enhance console visibility but actually functions as a Windows information stealer. This package collects sensitive data, including Discord tokens and passwords, and exfiltrates it to a Discord webhook.
Understanding the Risks
The ongoing activities of the Lazarus Group and similar threat actors highlight the vulnerabilities in open-source ecosystems. Developers must be vigilant when downloading packages, especially those that appear to be linked to job opportunities or are from less-known sources. The complexity and modularity of the malware used in these campaigns suggest that users should adopt a cautious approach to software installation.
Organizations and developers should implement strict monitoring of package dependencies and ensure that they are using trusted sources. The presence of malicious packages in widely used repositories like npm and PyPI underscores the importance of maintaining a robust security posture and being aware of potential threats from state-sponsored actors.
Key Takeaways
- Verify the source of any npm or PyPI packages before installation to avoid malicious software.
- Monitor your development environment for unusual activity that may indicate a RAT infection.
- Educate your team about the risks of fake job offers and how to identify them.
- Implement strict controls and audits on package dependencies in your projects.
- Regularly update software and security measures to protect against evolving threats.
Key Terms & Concepts
- Lazarus Group: In this article, Lazarus Group refers to a North Korea-linked threat actor known for sophisticated cyber attacks.
- Remote Access Trojan (RAT): A RAT is a type of malware that allows an attacker to remotely control an infected computer.
- Command-and-Control (C2) Server: A C2 server is a system used by attackers to send commands to compromised devices and receive data from them.
- Token-Based Mechanism: In this context, a token-based mechanism is a method used to authenticate requests between infected systems and a C2 server.
- npm and PyPI: npm and PyPI are popular package repositories for JavaScript and Python, respectively, where developers can share and download code packages.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.