Microsoft cuts API key lifetimes after North Korean npm attack

16 sources
  • Microsoft announced Aug. 4 it will shorten NuGet.org API key lifetimes after North Korean hackers poisoned 131 Mastra AI framework packages on npm.
  • CrowdStrike reported Aug. 3 that 87% of software-registry threats in the first half of 2026 involved npm packages, with AI pipelines now direct targets.
  • Developers who installed any @mastra package on or after June 17 have been urged by multiple security firms to rotate all credentials immediately.
Sources (16)
  1. 1 Microsoft shortens NuGet API key lifetime to improve ... www.helpnetsecurity.com
  2. 2 131 Poisoned AI Packages Hit Microsoft's (MSFT) npm. CrowdStrike (CRWD) Couldn't Ask for a Better Sales Pitch finance.yahoo.com
  3. 3 AI widely used to exploit critical flaws, disrupt supply chains www.cybersecuritydive.com
  4. 4 CrowdStrike 2026 Threat Hunting Report: AI is Now Embedded Across ... www.crowdstrike.com
  5. 5 Mastra npm Scope Takeover | Snyk snyk.io
  6. 6 Mastra npm Org Compromised: Multiple Packages Trojanized to ... www.endorlabs.com
  7. 7 From package to postinstall payload: Inside the Mastra npm supply chain ... www.microsoft.com
  8. 8 CrowdStrike finds AI systems under direct attack as exploit windows shrink siliconangle.com
  9. 9 North Korean Hackers Blamed for Mastra NPM Supply Chain Attack www.securityweek.com
  10. 10 North Korean Hackers Poison npm Packages with Malware www.linkedin.com
  11. 11 Mastra npm Supply Chain Attack: 140+ Packages Backdoored via easy-day ... www.stepsecurity.io
  12. 12 Amazon identifies North Korean hacker group behind open-source ... aws.amazon.com
  13. 13 CrowdStrike 2026 Threat Hunting Report: Exploitation Window Closes ... www.crowdstrike.com
  14. 14 npm Supply Chain Attack: North Korea Hits Mastra AI [2026] - Tech Insider tech-insider.org
  15. 15 North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal ... thehackernews.com
  16. 16 Mastra package supply chain attack: what did practitioners miss? nhimg.org