145 Mastra npm Packages Compromised in Supply Chain Attack, Crypto-Stealer Deployed
On June 17, 2026, a software supply chain attack codenamed 'easy-day-js' compromised 145 npm packages under the @mastra/* namespace, a popular open-source…
On June 17, 2026, a software supply chain attack codenamed 'easy-day-js' compromised 145 npm packages under the @mastra/* namespace, a popular open-source…
Microsoft assesses with high confidence that the Mastra npm compromise is attributable to Sapphire Sleet, a North Korean threat actor known for…
UNC1069 is a threat group attributed to North Korea, associated with the WAVESHAPER.V2 backdoor and activities overlapping with Sapphire Sleet. It has…
Famous Chollima is the name used by CrowdStrike to describe North Korea's IT worker operation, which involves placing operatives in companies worldwide…
Cybersecurity researchers at JFrog have uncovered a set of malicious npm packages that masquerade as legitimate PostCSS tools to deliver a Windows-based…