Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data

    June 22, 2026

    Musk Furious After SpaceX Stock Get Worst Possible Environmental Grade

    June 22, 2026

    This modular robot mower handles up to 6 acres, and it’s $1,000 off for Prime Day

    June 22, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»North Korean Hackers Blamed for Mastra NPM Supply Chain Attack
    North Korean Hackers Blamed for Mastra NPM Supply Chain Attack
    Cybersecurity

    North Korean Hackers Blamed for Mastra NPM Supply Chain Attack

    The Tech GuyBy The Tech GuyJune 22, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    The North Korean state-sponsored threat actor Sapphire Sleet is behind the Mastra supply chain attack that hit over 140 NPM packages last week, Microsoft reports.

    Advertisement

    Mastra is an open source TypeScript framework for building AI agents, workflows, and RAG pipelines. It offers integrations for major LLM providers, MCP servers, and cloud deployments.

    The supply chain attack occurred on June 17. During a 45-minute window, the hackers published 141 packages that contained the malicious dependency easy-day-js, a typosquat of the legitimate dayjs date library.

    The affected Mastra packages have approximately 8 million weekly downloads. All users who installed a @mastra package during the attack window on June 17 should consider their systems affected.

    As part of the attack, the hackers compromised the ‘ehindero’ NPM maintainer account, which has publishing rights across the Mastra ecosystem. One day before the account takeover, the attackers published a clean version of easy-day-js to a separate account, ‘sergey2016’.

    The threat actor used the compromised maintainer account to add easy-day-js as a dependency to 141 NPM packages across the Mastra ecosystem, in such a manner that the latest version of the library would always be installed, and then published the modified packages to NPM.

    Advertisement. Scroll to continue reading.

    Simultaneously, they published a new, malicious version of the easy-day-js library to their account.

    An obfuscated postinstall dropper in the dependency would fetch a second-stage payload from the attackers’ servers, write it to the temp directory, execute it as a detached, hidden background process, and then delete itself to hide its tracks.

    “Because the payload executes during installation, any developer workstation or continuous integration and continuous delivery (CI/CD) pipeline that ran npm install or npm update after the compromised versions were published was potentially exposed, regardless of whether the package was imported in application code,” Microsoft says.

    Targeting Windows, macOS, and Linux, the malware was designed to masquerade as node-related tools while collecting system information and targeting more than 160 cryptocurrency-related browser extensions.

    Microsoft has attributed the attack to the financially motivated North Korean group Sapphire Sleet, also known as BlueNoroff, CageyChameleon, Copernicium, and Stardust Chollima, which was also blamed for the Axios supply chain attack.

    In April, hackers published modified versions of the Axios NPM library that were pointing to a phantom dependency designed to download and execute a cross-platform RAT. Google’s Threat Intelligence Group attributed the attack to UNC1069.

    Mastra users are advised to remove the affected package versions, check their systems for malware, rotate credentials, tokens, and other secrets, and harden access to their crypto-wallets.

    Cybersecurity firms Aikido, Ox, Socket, Sonatype, and StepSecurity have published technical details and indicators of compromise (IoCs) associated with the Mastra supply chain attack.

    Related: More Cybersecurity Firms Disclose Impact From Klue Hack

    Related: CryptoBandits Malware Doubles as a Backdoor, Abuses Tor

    Related: NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks

    Related: Supply Chain Attack Hits 32 Red Hat NPM Packages

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data

    June 22, 2026

    15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown 

    June 20, 2026

    Cisco to Acquire WideField Security to Boost Splunk’s Agentic SOC

    June 20, 2026

    French President Urges US to Share Cutting-Edge AI and Democracies to Cooperate on Regulation

    June 20, 2026

    Cybersecurity Firms Impacted by Klue Supply Chain Attack

    June 20, 2026

    CryptoBandits Malware Doubles as a Backdoor, Abuses Tor

    June 19, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 202672 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 202618 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data

    June 22, 2026

    Musk Furious After SpaceX Stock Get Worst Possible Environmental Grade

    June 22, 2026

    This modular robot mower handles up to 6 acres, and it’s $1,000 off for Prime Day

    June 22, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.