Sapphire Sleet Mastra npm supply-chain campaign
Campaign
Summary
Hide ▲
Show ▼
The Mastra AI supply-chain campaign was attributed to Sapphire Sleet / BlueNoroff after Microsoft said the operation compromised the npm maintainer account "ehindero" and pushed malicious updates into the @mastra scope. The poisoned packages introduced easy-day-js, a typosquat of dayjs, which ran a postinstall hook, reached attacker-controlled C2 infrastructure, and delivered a cross-platform stealer to Windows, Linux, and macOS systems. The activity targeted developers and checked for 166 cryptocurrency wallet extensions, including MetaMask, Phantom, Coinbase Wallet, Binance Wallet, and TronLink. The campaign affected more than 140 npm packages and created exposure to credential theft, API key theft, authentication token theft, and wallet theft.
Related Happenings
SeasonalInvite eCard phishing campaign targeting Windows and macOS users
Campaign
H score30
First: 15.07.2026 18:00
Last: 15.07.2026 18:00
Sources 1
About this happening:
The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...
SeasonalInvite eCard phishing campaign targeting Windows and macOS users
CampaignAbout this happening: The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...
AsyncAPI repositories and npm publishing workflow hit by network compromise
Incident
H score27
First: 15.07.2026 12:16
Last: 15.07.2026 12:16
Sources 1
About this happening:
The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...
AsyncAPI repositories and npm publishing workflow hit by network compromise
IncidentAbout this happening: The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...
Injective Labs SDK project GitHub repository hit by network compromise
Incident
H score21
First: 09.07.2026 23:10
Last: 09.07.2026 23:10
Sources 1
About this happening:
The Injective Labs SDK project suffered a GitHub repository compromise that let attackers publish a malicious @injectivelabs/sdk-ts v1.20.21 package, putting developer...
Injective Labs SDK project GitHub repository hit by network compromise
IncidentAbout this happening: The Injective Labs SDK project suffered a GitHub repository compromise that let attackers publish a malicious @injectivelabs/sdk-ts v1.20.21 package, putting developer...
Malicious npm and PyPI Paysafe, Skrill, and Neteller SDK packages delivering stealer malware
Malware Activity
H score37
First: 08.07.2026 22:54
Last: 08.07.2026 22:54
Sources 1
About this happening:
Malicious npm and PyPI packages impersonating Paysafe, Skrill, and Neteller SDKs delivered stealer malware that siphoned secrets from developer environment...
Malicious npm and PyPI Paysafe, Skrill, and Neteller SDK packages delivering stealer malware
Malware ActivityAbout this happening: Malicious npm and PyPI packages impersonating Paysafe, Skrill, and Neteller SDKs delivered stealer malware that siphoned secrets from developer environment...
Postcss-minify-selector-parser Windows RAT delivery chain
Malware Activity
H score29
First: 23.06.2026 18:00
Last: 23.06.2026 18:00
Sources 1
About this happening:
The postcss-minify-selector-parser npm package delivered a multi-stage Windows RAT, creating a supply-chain path onto developer machines and exposing browser logins*...
Postcss-minify-selector-parser Windows RAT delivery chain
Malware ActivityAbout this happening: The postcss-minify-selector-parser npm package delivered a multi-stage Windows RAT, creating a supply-chain path onto developer machines and exposing browser logins*...
Timeline
-
19.06.2026 03:00 3 articles · 27d ago
Microsoft attributes Mastra AI npm supply-chain compromise to Sapphire Sleet
Attribution UpdateMicrosoft attributed the Mastra AI supply-chain compromise affecting more than 140 npm packages to Sapphire Sleet, also known as BlueNoroff, and said attackers compromised the npm maintainer account "ehindero" to publish malicious updates across the @mastra scope. The poisoned packages injected easy-day-js, a typosquat of dayjs, and the install chain deployed a cross-platform stealer aimed at credentials, API keys, authentication tokens, and cryptocurrency wallets on Windows, Linux, and macOS systems.
Show sources
- Microsoft links Mastra AI supply chain attack to North Korean hackers — www.bleepingcomputer.com — 20.06.2026 17:09
- Microsoft links Mastra AI supply chain attack to North Korean hackers — www.bleepingcomputer.com — 20.06.2026 17:09
- Microsoft Attributes Mastra AI Supply Chain Attack to North Korea — www.infosecurity-magazine.com — 22.06.2026 14:30