Microsoft verkürzt API-Schlüssel-Laufzeiten nach nordkoreanischem npm-Angriff

16 Quellen
  • Microsoft kündigte am 4. August an, die Laufzeiten für NuGet.org API-Schlüssel zu verkürzen, nachdem nordkoreanische Hacker 131 Mastra AI-Framework-Pakete auf npm infiziert hatten.
  • CrowdStrike berichtete am 3. August, dass 87 % der Bedrohungen für Software-Register in der ersten Jahreshälfte 2026 npm-Pakete betrafen, wobei KI-Pipelines nun direkte Ziele sind.
  • Entwickler, die am oder nach dem 17. Juni ein @mastra-Paket installiert haben, werden von mehreren Sicherheitsfirmen dringend aufgefordert, alle Anmeldedaten sofort zu rotieren.
Quellen (16)
  1. 1 Microsoft shortens NuGet API key lifetime to improve ... www.helpnetsecurity.com
  2. 2 131 Poisoned AI Packages Hit Microsoft's (MSFT) npm. CrowdStrike (CRWD) Couldn't Ask for a Better Sales Pitch finance.yahoo.com
  3. 3 AI widely used to exploit critical flaws, disrupt supply chains www.cybersecuritydive.com
  4. 4 CrowdStrike 2026 Threat Hunting Report: AI is Now Embedded Across ... www.crowdstrike.com
  5. 5 Mastra npm Scope Takeover | Snyk snyk.io
  6. 6 Mastra npm Org Compromised: Multiple Packages Trojanized to ... www.endorlabs.com
  7. 7 From package to postinstall payload: Inside the Mastra npm supply chain ... www.microsoft.com
  8. 8 CrowdStrike finds AI systems under direct attack as exploit windows shrink siliconangle.com
  9. 9 North Korean Hackers Blamed for Mastra NPM Supply Chain Attack www.securityweek.com
  10. 10 North Korean Hackers Poison npm Packages with Malware www.linkedin.com
  11. 11 Mastra npm Supply Chain Attack: 140+ Packages Backdoored via easy-day ... www.stepsecurity.io
  12. 12 Amazon identifies North Korean hacker group behind open-source ... aws.amazon.com
  13. 13 CrowdStrike 2026 Threat Hunting Report: Exploitation Window Closes ... www.crowdstrike.com
  14. 14 npm Supply Chain Attack: North Korea Hits Mastra AI [2026] - Tech Insider tech-insider.org
  15. 15 North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal ... thehackernews.com
  16. 16 Mastra package supply chain attack: what did practitioners miss? nhimg.org