FeedMicrosoft links Mastra AI supply chain attack to North Korea...
Bleeping Computer
9.5CRITICAL

Microsoft links Mastra AI supply chain attack to North Korean hackers

📅 20 June 2026 at 14:09 UTC📰 Bleeping ComputerView original source ↗
Microsoft links Mastra AI supply chain attack to North Korean hackers

Microsoft has attributed a recent Mastra AI supply chain attack that compromised more than 140 npm packages to the North Korean hacking group Sapphire Sleet, also known as BlueNoroff. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

A North Korean state-sponsored threat actor, Sapphire Sleet, attributed a Mastra AI supply chain attack that compromised over 140 npm packages, targeting financial sector systems with a cross-platform information stealer designed to steal sensitive credentials and cryptocurrency assets.

⚙️Technical Details
Affected Systems
WindowsLinuxmacOS
Attack Vectors
npm package updatesmalicious dependency injectionpost-install hook execution
💥Impact Assessment
Severity: critical
Who Is at Risk
Financial sector systems and individuals with cryptocurrency wallets
🛡️Recommended Actions
1Monitor npm package updates for suspicious activity
2Implement strict access controls on developer accounts
3Regularly update software dependencies to patch vulnerabilities
📦Affected Products
Mastra AInpm packages

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer
← Back to feed