www.securityweek.com 6/22/2026, 11:30:56 AM · external

North Korean Group Targets NPM Supply Chain, 8M Devs at Risk

North Korean Group Targets NPM Supply Chain, 8M Devs at Risk
Developing story incident 2 articles tracked
North Korean hackers compromise Mastra via malicious npm packages
CyberSIXT Evidence Panel
Primary Source microsoft.com
Threat Actor

MICROSOFT reports that the North Korean group Sapphire Sleet conducted a supply chain attack affecting over 140 NPM packages linked to the Mastra open-source framework on June 17. The attackers utilized a compromised maintainer account to introduce a malicious dependency, 'easy-day-js', masquerading as a legitimate library. This malicious package executed harmful payloads during installation, potentially exposing developer environments across Windows, macOS, and Linux systems.

Users who downloaded the affected packages, which had approximately 8 million weekly downloads, are advised to take immediate action to secure their systems, including removing the malicious versions and rotating sensitive credentials.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline