[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fCKdRdyRMUCQHc7tZ_vvFAVVFsb2FcjILI5RUVBJM2ZA":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"f71876e3-0704-4bfa-a210-e72aad5578d4","north-korean-hackers-poison-140-npm-packages-in-mastra-supply-chain-attack","5abd663a-852c-42fc-bb5a-42ae3ae2a28c","North Korean Hackers Poison 140+ NPM Packages in Mastra Supply Chain Attack","Sapphire Sleet, a North Korean state-sponsored group, compromised over 140 Mastra NPM packages by injecting a malicious dependency ('easy-day-js') that went undetected long enough to reach developer environments and CI\u002FCD pipelines. The attack exploited the inherent trust developers place in open-source package ecosystems, demonstrating how a single poisoned dependency can cascade across hundreds of downstream projects. The malware was engineered to harvest cryptocurrency wallet data and browser extension credentials across all major operating systems, making it a high-impact, cross-platform threat. This incident underscores why software supply chain integrity verification and real-time dependency monitoring are no longer optional for development teams.","**Immediate actions:**\n- Audit all current NPM dependencies for unexpected or recently added transitive dependencies such as 'easy-day-js'.\n- Pin dependency versions in package-lock.json or yarn.lock files and enforce integrity checks using `npm audit` or equivalent tools.\n- Revoke and rotate any credentials, API keys, or cryptocurrency wallet secrets accessible from affected build environments.\n\n**Long-term improvements:**\n- Implement a private package registry or proxy (e.g., Artifactory, Verdaccio) to vet and approve all third-party packages before use in CI\u002FCD pipelines.\n- Adopt a software composition analysis (SCA) tool (e.g., Snyk, Dependabot, OWASP Dependency-Check) integrated directly into your CI\u002FCD pipeline to flag malicious or vulnerable packages at build time.\n- Establish a formal third-party software supply chain risk policy requiring cryptographic signing and provenance verification (e.g., Sigstore\u002FCosign) for all consumed packages.\n\n**Detection measures:**\n- Enable real-time alerting on anomalous outbound network connections from CI\u002FCD build agents to detect data exfiltration attempts.\n- Monitor NPM package manifests for unexpected dependency additions or version changes using automated diff tooling in your pipeline.\n- Deploy endpoint detection on CI\u002FCD runners and developer workstations to identify malware behaviors such as credential harvesting or browser extension access.",[12,13,14,15,16,17,18,19,20],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 16: Application Software Security","NIST SP 800-161r1: Cybersecurity Supply Chain Risk Management","NIST SP 800-218 (SSDF): Secure Software Development Framework","NIST CSF DE.CM-3: Personnel activity is monitored to detect cybersecurity events","SLSA Supply Chain Levels for Software Artifacts (Level 3+)","GDPR Article 32: Security of Processing (for EU-affecting data exfiltration)","ITIL: Change and Release Management (dependency change controls)","OpenSSF Scorecard: Dependency pinning and vulnerability checks","published","2026-06-22T12:20:38.470164+00:00","2026-06-22T12:20:38.157+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fwww.securityweek.com\u002Fnorth-korean-hackers-blamed-for-mastra-npm-supply-chain-attack\u002F","north-korean-hackers-blamed-for-mastra-npm-supply-chain-attack-f461b5","North Korean Hackers Blamed for Mastra NPM Supply Chain Attack",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":42,"name":43,"slug":44,"description":45,"color":46},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[48],{"id":49,"date":50,"edition":51,"title":52,"audio_url":53},"96a7f278-52de-4002-b6b8-923cac680f66","2026-06-22","afternoon","ThreatNoir Afternoon Brief — June 22","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-06-22\u002Fthreatnoir-afternoon-brief-2026-06-22.mp3"]