Signal
North Korean hackers linked to malicious supply chain attack on Mastra AI framework
Evidence first: scan the strongest sources, then decide whether to go deeper.
Published 2026-06-22 11:10 UTCUpdated 2026-06-23 01:48 UTC
rss
cveexploitsmalwarethreat_actorssupply_chain_attackincident_response
Trend in the last 24h
Current brief openSource links open
This current signal is open on the public brief with summary, metadata, source links, and full evidence. Pro adds compare-over-time, alerts, exports, and workflow.
No card needed for the free brief.
Evidence trail (top sources)
top sources (3 domains)domains are deduped. counts indicate coverage, not truth.3 top sources shown
Overview
Security researchers have attributed a significant supply chain attack on the Mastra AI development environment to North Korean threat actors.
Entities
MicrosoftMastraSapphire SleetBlueNoroff
Score total
1.17
Momentum 24h
3
Posts
3
Origins
3
Source types
1
Duplicate ratio
0%
Why now
- Attack recently uncovered with over 140 malicious npm packages identified.
- North Korean threat actors increasingly targeting software supply chains for espionage and financial gain.
- Microsoft's attribution to Sapphire Sleet confirms ongoing cyber operations by North Korean groups against AI ecosystems.
Why it matters
- Highlights the growing threat of state-sponsored supply chain attacks targeting AI development tools.
- Demonstrates risks to developers relying on open-source packages from compromised maintainers.
- Underscores the need for enhanced security practices in software supply chains to prevent credential theft and backdoors.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
- North Korean hackers compromised Mastra npm maintainer account to inject malicious code into over 140 packages
- Malicious packages contained credential stealers, backdoors, and payloads targeting cryptocurrency extensions
- Microsoft attributes the Mastra AI supply chain attack to North Korean threat actor Sapphire Sleet
How sources frame it
- Microsoft Security Researchers: neutral
This incident exemplifies the increasing use of supply chain attacks by state-sponsored groups to infiltrate AI development environments and steal credentials.
All evidence
All evidence
SecurityWeek
securityweek.com · securityweek.com · 2026-06-22 11:10 UTC
BankInfoSecurity
bankinfosecurity.com · bankinfosecurity.com · 2026-06-23 01:48 UTC
Infosecurity Magazine
infosecurity-magazine.com · infosecurity-magazine.com · 2026-06-22 11:30 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 3Origin domains: 3Duplicates: -
Showing 3 / 0
Top publishers (this list)
- securityweek.com (1)
- bankinfosecurity.com (1)
- infosecurity-magazine.com (1)
Top origin domains (this list)
- securityweek.com (1)
- bankinfosecurity.com (1)
- infosecurity-magazine.com (1)