North Korea Attribution Expands Mastra Poisoning Risk

The real risk is no longer just a bad npm update. Microsoft now ties the Mastra package poisoning to Sapphire Sleet, which turns a supply-chain disclosure into a financially driven theft campaign aimed at developer secrets, API keys, and crypto wallets. More than 140 @mastra packages were updated with the typosquatted easy-day-js dependency. When installed, it ran a postinstall hook, dropped malware on developer devices, and then collected host data, browser history, installed apps, and wallet-extension checks across Windows, Linux, and macOS. That shifts the response from removing one malicious package to assuming some install environments were already exposed. Any workstation or CI runner that pulled the tainted releases may have leaked credentials or wallet access before the code was ever imported.

Part of the PlainSec briefing for 2026-06-22

Sources