Signal

North Korean hackers linked to malicious supply chain attack on Mastra AI framework

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-06-22 11:10 UTCUpdated 2026-06-23 01:48 UTC
rss
cveexploitsmalwarethreat_actorssupply_chain_attackincident_response
Source links open
Source links and full evidence are open here. Pro adds archive history, compare-over-time, alerts, exports, and workflow. Business adds Feed API integrations and team usage.
No card needed for the free brief.
Evidence trail (top sources)
top sources (3 domains)domains are deduped. counts indicate coverage, not truth.
3 top sources shown
North Korean Hackers Poison Mastra AI Framework
BankInfoSecurity · News · bankinfosecurity.com · 2026-06-23 01:48 UTC
Overview

Security researchers have attributed a significant supply chain attack on the Mastra AI development environment to North Korean threat actors.

Entities
MicrosoftMastraSapphire SleetBlueNoroff
Score total
1.17
Momentum 24h
3
Posts
3
Origins
3
Source types
1
Duplicate ratio
0%
Why now
  • Attack recently uncovered with over 140 malicious npm packages identified.
  • North Korean threat actors increasingly targeting software supply chains for espionage and financial gain.
  • Microsoft's attribution to Sapphire Sleet confirms ongoing cyber operations by North Korean groups against AI ecosystems.
Why it matters
  • Highlights the growing threat of state-sponsored supply chain attacks targeting AI development tools.
  • Demonstrates risks to developers relying on open-source packages from compromised maintainers.
  • Underscores the need for enhanced security practices in software supply chains to prevent credential theft and backdoors.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
  • North Korean hackers compromised a Mastra npm maintainer account to inject malicious code into over 140 npm packages.
  • The malicious packages distributed credential-stealing tools and backdoors targeting cryptocurrency extensions.
  • Microsoft attributed the attack to the North Korean threat actor Sapphire Sleet (BlueNoroff).
How sources frame it
  • Microsoft Security Researchers: neutral
All evidence
All evidence
North Korean Hackers Poison Mastra AI Framework
BankInfoSecurity · bankinfosecurity.com · 2026-06-23 01:48 UTC
Microsoft Attributes Mastra AI Supply Chain Attack to North Korea
Infosecurity Magazine · infosecurity-magazine.com · 2026-06-22 11:30 UTC
North Korean Hackers Blamed for Mastra NPM Supply Chain Attack
SecurityWeek · securityweek.com · 2026-06-22 11:10 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 3Origin domains: 3Duplicates: -
Showing 3 / 3
Top publishers (this list)
  • BankInfoSecurity (1)
  • Infosecurity Magazine (1)
  • SecurityWeek (1)
Top origin domains (this list)
  • bankinfosecurity.com (1)
  • infosecurity-magazine.com (1)
  • securityweek.com (1)