Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedhigh

Microsoft links Mastra AI supply chain attack to North Korean hackers

Microsoft attributed a Mastra AI supply chain attack that compromised over 140 npm packages to North Korean hacking group Sapphire Sleet (BlueNoroff). The attack targeted the npm ecosystem and AI development infrastructure.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
140+ npm packages compromised; potential impact on AI/ML development workflows
Ecosystems
Attack vectors
Threat actor
Affected entities
  • Mastra AISupply chain compromised; 140+ npm packages affected

Microsoft has linked a recent supply chain attack targeting Mastra AI to the North Korean hacking group Sapphire Sleet, also known as BlueNoroff. The attack compromised more than 140 npm packages, indicating a significant breach of the JavaScript/Node.js ecosystem.\n\nThe compromise of Mastra AI's supply chain represents a serious threat to developers and organizations relying on affected npm packages. With over 140 packages impacted, the attack has broad potential reach across the npm ecosystem and AI/ML development communities.\n\nMicrosoft's attribution to a state-sponsored North Korean actor suggests this was a targeted, sophisticated operation rather than opportunistic malware distribution.

Indicators of compromise

Packages
  • Mastra AI npm packages (140+ affected, specific names not listed in source)

Remediation

  • Audit all dependencies on affected Mastra AI npm packages immediately
  • Update to patched versions of all compromised packages once available
  • Review npm package integrity and verify package signatures
  • Monitor for suspicious activity in projects using Mastra AI packages
  • Consider implementing additional supply chain security controls and package verification mechanisms

Sources

  1. Microsoft links Mastra AI supply chain attack to North Korean hackers · BleepingComputer

Cite this entry

"Microsoft links Mastra AI supply chain attack to North Korean hackers." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed June 20, 2026; last updated June 20, 2026. https://supplychainattack.org/incident/microsoft-links-mastra-ai-supply-chain-attack-to-north-korean-hackers-18qpwu

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. activecritical

    ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2

    ChainDrop is a self-propagating npm worm that publishes malicious versions of dozens of npm packages using stolen maintainer credentials. The worm harvests CI/CD credentials and uses an Ethereum-based dead-drop command-and-control mechanism.

    ChaindropnpmOtherCompromised packageMalicious maintainerAccount takeover
  2. resolvedhigh

    Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers

    Amazon attributed multiple high-profile npm supply chain attacks targeting the Debug and Chalk packages to North Korean threat actors. The incidents involved compromised packages in the npm ecosystem with significant downstream impact.

    Lazarus GroupnpmCompromised packageMalicious maintainer
  3. resolvedcritical

    Malicious code in xerohub-discord-voice-v3 (npm)

    The npm package xerohub-discord-voice-v3 contained malicious code that exfiltrated Discord user authentication tokens to a hardcoded webhook URL controlled by the package author. The startVoiceJoiner() function unconditionally sent raw tokens, usernames, guild IDs, and voice channel IDs to discord.com/api/webhooks/1528726419046404196 before executing any legitimate voice functionality.

    npmCompromised packageMalicious maintainer
  4. activecritical

    Malicious code in @cap-js/openapi (npm)

    The npm package @cap-js/openapi was compromised and found to contain malicious code. The package steals credentials and propagates them to other packages it has access to, with persistence mechanisms. This is attributed to the "Mini Shai-Hulud is back" worm campaign by the TeamPCP threat actor.

    Mini Shai HuludTeamPCPnpmCompromised packageMalicious maintainer