Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

helpnetsecurity+1cybersecuritydive+1snyk+1A North Korea-linked hacking group compromised more than 130 packages within the Mastra AI framework on npm, the JavaScript package registry owned by Microsoft through GitHub, in what multiple security firms have called one of the largest open-source supply chain attacks of 2026.
CrowdStrike Holdings identified the group — tracked as Stardust Chollima — as having injected a malicious dependency into 131 trusted Mastra AI framework packages, according to the company's 2026 Threat Hunting Report released on August 3. Microsoft's own investigation, published on June 17, attributed the attack to a group it calls Sapphire Sleet and identified more than 140 affected packages.microsoft+3
The attackers used stolen maintainer credentials to republish the entire @mastra npm scope, adding a previously unknown dependency called "easy-day-js" that executed during installation. The malicious code disabled security checks, connected to attacker-controlled servers, and delivered malware targeting cryptocurrency wallets including MetaMask, Phantom, and Coinbase Wallet. Security firm Snyk reported that the compromised packages were pushed in under 30 minutes.linkedin+2
The breach has prompted Microsoft to tighten security across its developer ecosystem. On August 4, the company announced it would reduce the lifetime of NuGet.org API keys from 365 days to 30 days starting August 17, citing the Mastra compromise and a separate attack on the NX Console npm package as motivating incidents. Microsoft is also pushing developers toward its Trusted Publishing system, introduced in September 2025, which replaces permanent API keys with temporary OpenID Connect tokens.helpnetsecurity
CrowdStrike's report found that 87 percent of identified software-registry threats in the first half of 2026 involved npm packages. Amazon separately confirmed in late July that supply chain attacks linked to North Korean groups had increased in both volume and sophistication.finance.yahoo+2
The incident underscores a tension at the heart of Microsoft's developer business: the company owns the registry infrastructure where the attack occurred and simultaneously sells the security tools designed to detect it. Microsoft Defender Antivirus, Defender for Endpoint, and Defender XDR all now carry detections for the Mastra payload.microsoft
CrowdStrike, which reported fiscal Q1 2027 revenue of $1.39 billion — up 26 percent year over year — positioned the findings as evidence that AI development pipelines are now direct targets for nation-state actors. "Adversaries are targeting trusted users and tools across identity systems, cloud environments, SaaS applications, AI services, software supply chains," the company said in its report.crowdstrike+2
Developers who installed any @mastra package on or after June 17, 2026, have been advised by multiple security firms to treat their machines as compromised and rotate all credentials immediately.snyk+1