Microsoft says a North Korean hacking group compromised the Mastra AI software supply chain by hijacking an npm maintainer account and pushing malicious updates to more than 140 packages. The attacker used the compromised account "ehindero" to add a typosquatted dependency, "easy-day-js," to packages in the @mastra scope; its post-install script dropped cross-platform malware for Windows, macOS, and Linux that stole credentials, API keys, authentication tokens, browser data, and cryptocurrency-wallet information, and established persistence on infected systems.
Why it matters: Developers and organizations that installed affected Mastra packages could have had secrets and crypto-wallet data stolen from their machines. This is urgent for software teams: identify any use of affected @mastra packages, remove malicious versions, rotate exposed credentials and tokens, and investigate systems that contacted the attackers' command-and-control servers.
2026.08.03
78% relevant
The Register article describes the same underlying North Korean campaign against AI-focused development environments, adding CrowdStrike's framing that Famous Chollima showed the most advanced AI usage and used trojanized GitHub repositories in January-February to target cryptocurrency and blockchain developers.
Bill Toulas
2026.07.30
68% relevant
This article does not cover the same package compromise, but it materially extends the broader Sapphire Sleet npm supply-chain campaign by linking the earlier typo-crypto, debug, chalk, and axios compromises to the same North Korean actor and describing the social-engineering and maintainer-compromise methods used.
2026.07.30
54% relevant
This report expands on the same North Korea-linked actor, Sapphire Sleet, by attributing additional npm compromises—typo-crypto, debug, chalk, and axios—to the group and describing the maintainer social-engineering method used to publish malicious updates.
Ionut Arghire
2026.06.22
98% relevant
This article covers the same Mastra npm supply-chain compromise and adds concrete details on the June 17 attack window, the compromised 'ehindero' maintainer account, the typosquatted easy-day-js dependency, cross-platform postinstall payload behavior, and crypto-extension targeting.
Lawrence Abrams
2026.06.20
100% relevant
This article establishes a distinct tracked story by adding high-confidence attribution of the Mastra AI npm compromise to Sapphire Sleet and detailing the attack chain, malware capabilities, and follow-on activity.
← Back to all stories