this post was submitted on 05 Mar 2026
10 points (100.0% liked)

Technology

1387 readers
22 users here now

A tech news sub for communists

founded 3 years ago
MODERATORS
 

ReversingLabs uncovered the "graphalgo" campaign by North Korea's Lazarus Group, active since May 2025, targeting crypto developers via fake job offers on LinkedIn, Facebook, and Reddit. Posing as firms like "Veltrix Capital," attackers provide GitHub tasks with malicious npm and PyPI dependencies (e.g., graphalgo, bigmathutils) that install RATs checking for MetaMask and enabling remote control. The modular setup uses indirect payload delivery for persistence, with IoCs including codepool.cloud and listed package hashes.

no comments (yet)
sorted by: hot top controversial new old
there doesn't seem to be anything here