Vulnerabilities · 84 days ago
The real risk is no longer just a bad npm update. Microsoft now ties the Mastra package poisoning to Sapphire Sleet, which turns a supply-chain disclosure into a financially driven theft campaign aimed at developer secrets, API keys, and crypto wallets.
More than 140 @mastra packages were updated with the typosquatted easy-day-js dependency. When installed, it ran a postinstall hook, dropped malware on developer devices, and then collected host data, browser history, installed apps, and wallet-extension checks across Windows, Linux, and macOS.
That shifts the response from removing one malicious package to assuming some install environments were already exposed. Any workstation or CI runner that pulled the tainted releases may have leaked credentials or wallet access before the code was ever imported.
7 sources covering this story
Microsoft Attributes Mastra AI Supply Chain Attack to North Korea
North Korean threat actor Sapphire Sleet has been linked to a supply chain attack targeting Mastra, according to Microsoft security researchers
North Korean Hackers Blamed for Mastra NPM Supply Chain Attack
A malicious dependency the attackers added to over 140 Mastra packages fetches a payload targeting cryptocurrency extensions.
Microsoft links Mastra AI supply chain attack to North Korean hackers
Microsoft has attributed a recent Mastra AI supply chain attack that compromised more than 140 npm packages to the North Korean hacking group Sapphire Sleet, also known as BlueNoroff.
This report highlights how to detect, hunt, and defend against supply chain attacks using Microsoft Defender and actionable threat intelligence.
145 Mastra npm Packages Compromised via Hijacked Contributor Account
144 Mastra npm packages added easy-day-js malware, exposing developer systems and CI runners to infostealer risks.
140+ Mastra npm Packages Compromised in Coordinated Supply C...
More than 140 Mastra npm packages were compromised in a supply chain attack that used a typosquatted dependency to deliver a cross-platform infosteale...
Mastra npm Scope Takeover | Snyk
A dormant contributor account was used to republish the entire @mastra npm scope (more than 100 packages), each injected with a single dependency, easy-day-js, that drops a cross-platform cryptocurrency stealer.
Part of the PlainSec briefing for 2026-06-22