logo

North Korean Hackers Exploit Mastra npm Supply Chain to Target Developers

ID: c01739d6-e186-5e1a-b88d-61b78bdd823e

STIX ID: report--c01739d6-e186-5e1a-b88d-61b78bdd823e

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-06-22

Date Updated: 2026-06-22

...
...

Microsoft Defender Security Research Team attributed a supply-chain attack on the Mastra open-source TypeScript ecosystem to North Korean state actor Sapphire Sleet; attackers compromised an npm maintainer account to poison over 140 packages, publishing malicious code that disabled TLS certificate verification and aimed to steal cryptocurrency and collect reconnaissance data, prompting Microsoft to issue protections and warnings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.