North Korean Hackers Poison 140+ NPM Packages in Mastra Supply Chain Attack
Sapphire Sleet, a North Korean state-sponsored group, compromised over 140 Mastra NPM packages by injecting a malicious dependency ('easy-day-js') that went undetected long enough to reach developer environments and CI/CD pipelines. The attack exploited the inherent trust developers place in open-source package ecosystems, demonstrating how a single poisoned dependency can cascade across hundreds of downstream projects. The malware was engineered to harvest cryptocurrency wallet data and browser extension credentials across all major operating systems, making it a high-impact, cross-platform threat. This incident underscores why software supply chain integrity verification and real-time dependency monitoring are no longer optional for development teams.
Tactical Insight
Immediate actions
- Audit all current NPM dependencies for unexpected or recently added transitive dependencies such as 'easy-day-js'.
- Pin dependency versions in package-lock.json or yarn.lock files and enforce integrity checks using `npm audit` or equivalent tools.
- Revoke and rotate any credentials, API keys, or cryptocurrency wallet secrets accessible from affected build environments.
Long-term improvements
- Implement a private package registry or proxy (e.g., Artifactory, Verdaccio) to vet and approve all third-party packages before use in CI/CD pipelines.
- Adopt a software composition analysis (SCA) tool (e.g., Snyk, Dependabot, OWASP Dependency-Check) integrated directly into your CI/CD pipeline to flag malicious or vulnerable packages at build time.
- Establish a formal third-party software supply chain risk policy requiring cryptographic signing and provenance verification (e.g., Sigstore/Cosign) for all consumed packages.
Detection measures
- Enable real-time alerting on anomalous outbound network connections from CI/CD build agents to detect data exfiltration attempts.
- Monitor NPM package manifests for unexpected dependency additions or version changes using automated diff tooling in your pipeline.
- Deploy endpoint detection on CI/CD runners and developer workstations to identify malware behaviors such as credential harvesting or browser extension access.