Back to all lessons
Awareness Lessons
4 months ago

North Korean Hackers Poison 140+ NPM Packages in Mastra Supply Chain Attack

Sapphire Sleet, a North Korean state-sponsored group, compromised over 140 Mastra NPM packages by injecting a malicious dependency ('easy-day-js') that went undetected long enough to reach developer environments and CI/CD pipelines. The attack exploited the inherent trust developers place in open-source package ecosystems, demonstrating how a single poisoned dependency can cascade across hundreds of downstream projects. The malware was engineered to harvest cryptocurrency wallet data and browser extension credentials across all major operating systems, making it a high-impact, cross-platform threat. This incident underscores why software supply chain integrity verification and real-time dependency monitoring are no longer optional for development teams.

Tactical Insight

Immediate actions

  • Audit all current NPM dependencies for unexpected or recently added transitive dependencies such as 'easy-day-js'.
  • Pin dependency versions in package-lock.json or yarn.lock files and enforce integrity checks using `npm audit` or equivalent tools.
  • Revoke and rotate any credentials, API keys, or cryptocurrency wallet secrets accessible from affected build environments.

Long-term improvements

  • Implement a private package registry or proxy (e.g., Artifactory, Verdaccio) to vet and approve all third-party packages before use in CI/CD pipelines.
  • Adopt a software composition analysis (SCA) tool (e.g., Snyk, Dependabot, OWASP Dependency-Check) integrated directly into your CI/CD pipeline to flag malicious or vulnerable packages at build time.
  • Establish a formal third-party software supply chain risk policy requiring cryptographic signing and provenance verification (e.g., Sigstore/Cosign) for all consumed packages.

Detection measures

  • Enable real-time alerting on anomalous outbound network connections from CI/CD build agents to detect data exfiltration attempts.
  • Monitor NPM package manifests for unexpected dependency additions or version changes using automated diff tooling in your pipeline.
  • Deploy endpoint detection on CI/CD runners and developer workstations to identify malware behaviors such as credential harvesting or browser extension access.