Bleeping Computer
9.5 — CRITICAL
Microsoft links Mastra AI supply chain attack to North Korean hackers
Microsoft has attributed a recent Mastra AI supply chain attack that compromised more than 140 npm packages to the North Korean hacking group Sapphire Sleet, also known as BlueNoroff. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
A North Korean state-sponsored threat actor, Sapphire Sleet, attributed a Mastra AI supply chain attack that compromised over 140 npm packages, targeting financial sector systems with a cross-platform information stealer designed to steal sensitive credentials and cryptocurrency assets.
⚙️Technical Details
Affected Systems
WindowsLinuxmacOS
Attack Vectors
npm package updatesmalicious dependency injectionpost-install hook execution
💥Impact Assessment
Severity: critical
Who Is at Risk
Financial sector systems and individuals with cryptocurrency wallets
🛡️Recommended Actions
1Monitor npm package updates for suspicious activity
2Implement strict access controls on developer accounts
3Regularly update software dependencies to patch vulnerabilities
📦Affected Products
Mastra AInpm packages
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
