Microsoft says North Korea's Sapphire Sleet was behind the Mastra AI npm supply-chain attack affecting 140+ packages

Microsoft says a North Korean hacking group compromised the Mastra AI software supply chain by hijacking an npm maintainer account and pushing malicious updates to more than 140 packages. The attacker used the compromised account "ehindero" to add a typosquatted dependency, "easy-day-js," to packages in the @mastra scope; its post-install script dropped cross-platform malware for Windows, macOS, and Linux that stole credentials, API keys, authentication tokens, browser data, and cryptocurrency-wallet information, and established persistence on infected systems.
Why it matters: Developers and organizations that installed affected Mastra packages could have had secrets and crypto-wallet data stolen from their machines. This is urgent for software teams: identify any use of affected @mastra packages, remove malicious versions, rotate exposed credentials and tokens, and investigate systems that contacted the attackers' command-and-control servers.

Sources

North Korean Hackers Blamed for Mastra NPM Supply Chain Attack
Ionut Arghire 2026.06.22 98% relevant
This article covers the same Mastra npm supply-chain compromise and adds concrete details on the June 17 attack window, the compromised 'ehindero' maintainer account, the typosquatted easy-day-js dependency, cross-platform postinstall payload behavior, and crypto-extension targeting.
Microsoft links Mastra AI supply chain attack to North Korean hackers
Lawrence Abrams 2026.06.20 100% relevant
This article establishes a distinct tracked story by adding high-confidence attribution of the Mastra AI npm compromise to Sapphire Sleet and detailing the attack chain, malware capabilities, and follow-on activity.
← Back to all stories