Lazarus Campaign Plants Malicious Packages in npm and PyPI Ecosystems

Feb 12, 2026

Cybersecurity researchers have discovered a fresh set of malicious packages across npm and the Python Package Index (PyPI) repository linked to a fake recruitment-themed campaign orchestrated by the North Korea-linked Lazarus Group.
The coordinated campaign has been codenamed graphalgo in reference to the first package published in the npm registry. It’s assessed to be active since May 2025.

Get Free Report & Network Analysis

Please check your email for the free report.