Vulnerabilità · 99 giorni fa
Il punto non è più solo il package avvelenato: un’installazione npm può diventare il momento in cui una postazione di sviluppo o un runner CI viene trasformato in un bersaglio per rubare segreti. Qui il rischio si sposta dai file visibili della base di codice alle credenziali, alle sessioni browser e ai wallet già presenti sugli ambienti che hanno installato quei package.
Microsoft attribuisce con alta confidenza l’operazione a Sapphire Sleet, gruppo nordcoreano legato al settore finanziario. Oltre 140 package nel namespace @mastra hanno ricevuto un dependency malevolo, easy-day-js, che al post-install avvia un dropper e porta su Windows, Linux e macOS un infostealer capace di raccogliere token, API key, cronologie, processi e estensioni wallet; sulle macchine raggiunte compaiono anche tecniche di persistenza e componenti già associati al gruppo.
Per chi gestisce supply chain npm, il confine da monitorare non è il singolo package rimosso, ma ogni workstation o ambiente di build che lo ha installato: il furto dei segreti può essere già avvenuto prima della pulizia del repository. L’attribuzione sposta anche la lettura dell’episodio: non un incidente isolato di pubblicazione, ma una campagna di theft con obiettivo economico e crypto.
L'attribuzione a Sapphire Sleet indica che il furto di credenziali e wallet via package open source è un canale operativo, non un effetto collaterale.
7 fonti che coprono questa storia
Microsoft Attributes Mastra AI Supply Chain Attack to North Korea
North Korean threat actor Sapphire Sleet has been linked to a supply chain attack targeting Mastra, according to Microsoft security researchers
North Korean Hackers Blamed for Mastra NPM Supply Chain Attack
A malicious dependency the attackers added to over 140 Mastra packages fetches a payload targeting cryptocurrency extensions.
Microsoft links Mastra AI supply chain attack to North Korean hackers
Microsoft has attributed a recent Mastra AI supply chain attack that compromised more than 140 npm packages to the North Korean hacking group Sapphire Sleet, also known as BlueNoroff.
This report highlights how to detect, hunt, and defend against supply chain attacks using Microsoft Defender and actionable threat intelligence.
145 Mastra npm Packages Compromised via Hijacked Contributor Account
144 Mastra npm packages added easy-day-js malware, exposing developer systems and CI runners to infostealer risks.
140+ Mastra npm Packages Compromised in Coordinated Supply C...
More than 140 Mastra npm packages were compromised in a supply chain attack that used a typosquatted dependency to deliver a cross-platform infosteale...
Mastra npm Scope Takeover | Snyk
A dormant contributor account was used to republish the entire @mastra npm scope (more than 100 packages), each injected with a single dependency, easy-day-js, that drops a cross-platform cryptocurrency stealer.
Part of the PlainSec briefing for 2026-06-22