<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Microsoft Links Mastra AI Supply Chain Attack to North Korean Hackers

Microsoft links a supply chain attack on Mastra to North Korea's Sapphire Sleet, compromising npm packages to target crypto wallets.
Content Team

Microsoft has attributed a supply chain attack on Mastra — an open-source TypeScript framework for building AI applications — to North Korean state actor Sapphire Sleet, also tracked as APT38 and BlueNoroff. The attribution, made June 19 with "high confidence," came after attackers compromised an npm maintainer account and poisoned over 140 packages with malicious code that ran straight from a postinstall hook.

The malware targeted cryptocurrency wallets from 166 browser extensions, including MetaMask and Coinbase Wallet, while also stealing browser history and system data. It ran on Windows, macOS and Linux, and switched off TLS certificate verification before phoning home.

Developers should check for easy-day-js dependencies. Mastra 1.13.0 and earlier and @mastra/core 1.42.0 and earlier are unaffected — anything newer needs checking.

Source: Infosecurity Magazine

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo