Find notable cyber news and cases, enriched with sources, timelines, and signals.

Sapphire Sleet Mastra npm supply-chain campaign

Campaign
First reported
Last updated
Happening score
H score 42
2 unique sources, 2 articles

Summary

Hide ▲

The Mastra AI supply-chain campaign was attributed to Sapphire Sleet / BlueNoroff after Microsoft said the operation compromised the npm maintainer account "ehindero" and pushed malicious updates into the @mastra scope. The poisoned packages introduced easy-day-js, a typosquat of dayjs, which ran a postinstall hook, reached attacker-controlled C2 infrastructure, and delivered a cross-platform stealer to Windows, Linux, and macOS systems. The activity targeted developers and checked for 166 cryptocurrency wallet extensions, including MetaMask, Phantom, Coinbase Wallet, Binance Wallet, and TronLink. The campaign affected more than 140 npm packages and created exposure to credential theft, API key theft, authentication token theft, and wallet theft.

Related Happenings

SeasonalInvite eCard phishing campaign targeting Windows and macOS users

Campaign
H score30 First: 15.07.2026 18:00 Last: 15.07.2026 18:00 Sources 1

About this happening: The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...

AsyncAPI repositories and npm publishing workflow hit by network compromise

Incident
H score27 First: 15.07.2026 12:16 Last: 15.07.2026 12:16 Sources 1

About this happening: The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...

Injective Labs SDK project GitHub repository hit by network compromise

Incident
H score21 First: 09.07.2026 23:10 Last: 09.07.2026 23:10 Sources 1

About this happening: The Injective Labs SDK project suffered a GitHub repository compromise that let attackers publish a malicious @injectivelabs/sdk-ts v1.20.21 package, putting developer...

Malicious npm and PyPI Paysafe, Skrill, and Neteller SDK packages delivering stealer malware

Malware Activity
H score37 First: 08.07.2026 22:54 Last: 08.07.2026 22:54 Sources 1

About this happening: Malicious npm and PyPI packages impersonating Paysafe, Skrill, and Neteller SDKs delivered stealer malware that siphoned secrets from developer environment...

Postcss-minify-selector-parser Windows RAT delivery chain

Malware Activity
H score29 First: 23.06.2026 18:00 Last: 23.06.2026 18:00 Sources 1

About this happening: The postcss-minify-selector-parser npm package delivered a multi-stage Windows RAT, creating a supply-chain path onto developer machines and exposing browser logins*...

Timeline

  1. 19.06.2026 03:00 3 articles · 27d ago

    Microsoft attributes Mastra AI npm supply-chain compromise to Sapphire Sleet

    Attribution Update

    Microsoft attributed the Mastra AI supply-chain compromise affecting more than 140 npm packages to Sapphire Sleet, also known as BlueNoroff, and said attackers compromised the npm maintainer account "ehindero" to publish malicious updates across the @mastra scope. The poisoned packages injected easy-day-js, a typosquat of dayjs, and the install chain deployed a cross-platform stealer aimed at credentials, API keys, authentication tokens, and cryptocurrency wallets on Windows, Linux, and macOS systems.

    Show sources