All incidents

North Korean hackers compromise npm packages in supply chain attack

malwareopenJun 22, 2026 — Jul 30, 2026
North Korean hackers compromise npm packages in supply chain attack

NORTH Korean hackers have compromised more than 140 npm packages tied to the Mastra open‑source AI framework, inserting a malicious dependency that activates during installation Microsoft reported. The operation puts millions of developers at risk of credential theft and malware infection according to industry coverage.

The attackers added a package called easy‑day-js that disables TLS certificate verification and contacts a command‑and‑control server to deliver payloads designed to siphon data from cryptocurrency wallet browser extensions as detailed in the Microsoft advisory. No CVEs have been assigned to the flaw, which relies on a post‑install script rather than a traditional vulnerability.

Microsoft attributes the campaign to the group it tracks as Sapphire Sleet, also known as Stardust Chollima in its threat intelligence. The intrusion began with the compromise of an npm maintainer account, allowing the threat actors to publish tainted versions across the ecosystem.

Activity was first seen on 22 June 2026 and persisted until at least 30 July 2026, with the infected packages logging roughly eight million weekly downloads SecurityWeek noted. Reports indicate the attackers used social‑engineering lures via Amazon links to gain initial access to the maintainer credentials as highlighted by The Hacker News.

The malicious payload runs on Windows, macOS and Linux, seeking to exfiltrate secrets from popular wallet extensions and potentially giving the actors control over developer environments InfoSecurity Magazine explained. Organisations that consumed the affected versions should assume their build machines and any stored credentials may be compromised.

Defenders should audit their lockfiles and remove any instance of easy‑day-js, then scrutinise post‑install scripts in all dependencies for unexpected network calls per Microsoft guidance. Rotating API keys, passwords and any tokens used in the compromised projects is essential, as is implementing multi‑factor authentication on npm accounts. Monitoring outbound traffic to known malicious domains and enforcing strict package integrity checks can help prevent reinfection.

Microsoft advises maintaining an up‑to‑date software bill of materials, enforcing signature verification for installed packages and reviewing the security guidance published in its June blog post for detailed mitigation steps.

Intelligence briefing updated Jul 30, 2026

STARDUST CHOLLIMA
Root sourcewww.microsoft.com
Timeline Coverage

Swipe to explore timeline