North Korea-linked group tied to Mastra AI npm supply-chain attack

TL;DR Summary
Microsoft attributes the Mastra AI npm supply-chain attack to North Korea's Sapphire Sleet/BlueNoroff after attackers hijacked an npm maintainer to publish 140+ malicious Mastra packages; the malicious typosquat dependency easy-day-js drops a cross-platform info stealer that exfiltrates credentials and crypto-wallet data across Windows, Linux, and macOS, disables TLS verification, contacts attacker C2, and uses OS-specific persistence and a PowerShell backdoor.
- Microsoft links Mastra AI supply chain attack to North Korean hackers BleepingComputer
- From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet Microsoft
- Mastra npm Supply Chain Attack: 140+ Packages Backdoored via easy-day-js Typosquat StepSecurity
- 145 Mastra npm Packages Compromised via Hijacked Contributor Account The Hacker News
- North Korean hackers behind supply chain attack on AI platform: Microsoft NK News
Reading Insights
Total Reads
0
Unique Readers
19
Time Saved
4 min
vs 5 min read
Condensed
93%
818 → 60 words
Want the full story? Read the original article
Read on BleepingComputer