North Korean Hackers Exploit Mastra npm Supply Chain to Target Developers
ID: c01739d6-e186-5e1a-b88d-61b78bdd823e
STIX ID: report--c01739d6-e186-5e1a-b88d-61b78bdd823e
Feed Name: ThreatCluster
Threat Score
Microsoft Defender Security Research Team attributed a supply-chain attack on the Mastra open-source TypeScript ecosystem to North Korean state actor Sapphire Sleet; attackers compromised an npm maintainer account to poison over 140 packages, publishing malicious code that disabled TLS certificate verification and aimed to steal cryptocurrency and collect reconnaissance data, prompting Microsoft to issue protections and warnings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
