Signal
North Korean hackers linked to Mastra AI supply chain attack
Evidence first: scan the strongest sources, then decide whether to go deeper.
Published 2026-06-22 11:10 UTCUpdated 2026-06-22 11:30 UTC
rss
supply_chain_attackmalwarethreat_actorcryptocurrencynpmnorth_korea
Trend in the last 24h
Current brief openSource links open
This current signal is open on the public brief with summary, metadata, source links, and full evidence. Pro adds compare-over-time, alerts, exports, and workflow.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.2 top sources shown
limited source diversity in top sources
Overview
Microsoft security researchers have attributed a recent supply chain attack on Mastra, an AI-related project, to the North Korean threat actor known as Sapphire Sleet.
Entities
MicrosoftMastra
Score total
0.99
Momentum 24h
2
Posts
2
Origins
2
Source types
1
Duplicate ratio
0%
Why now
- Recent discovery of malicious dependency in over 140 Mastra packages.
- Microsoft's attribution to a known North Korean group highlights ongoing geopolitical cyber threats.
- Growing reliance on open-source AI tools increases potential attack surface.
Why it matters
- Supply chain attacks compromise trusted software components, amplifying impact.
- Targeting cryptocurrency extensions indicates financial motives linked to cyber espionage.
- State-sponsored actors like North Korea continue to exploit open-source ecosystems.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
- North Korean threat actor Sapphire Sleet conducted a supply chain attack on Mastra packages
How sources frame it
- Infosecurity Magazine: neutral
- SecurityWeek: neutral
All evidence
All evidence
Infosecurity Magazine
infosecurity-magazine.com · infosecurity-magazine.com · 2026-06-22 11:30 UTC
SecurityWeek
securityweek.com · securityweek.com · 2026-06-22 11:10 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
- infosecurity-magazine.com (1)
- securityweek.com (1)
Top origin domains (this list)
- infosecurity-magazine.com (1)
- securityweek.com (1)