Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
North Korean Hackers Linked to Major NPM Supply Chain Breach

North Korean Hackers Linked to Major NPM Supply Chain Breach

Posted on June 22, 2026 By CWS

North Korean state-sponsored hackers, identified as Sapphire Sleet, have been implicated in a significant attack on the Mastra open source framework, targeting over 140 NPM packages last week. According to Microsoft, the breach compromised software components used extensively by developers.

Understanding the Mastra Framework

Mastra serves as a TypeScript framework facilitating AI agents, workflows, and RAG pipelines. It integrates with leading large language model providers, MCP servers, and cloud services, making it a crucial tool for developers.

The attack unfolded on June 17, when the hackers released 141 packages, each containing a malicious dependency named easy-day-js, which mimicked the legitimate dayjs date library. This tactic, known as typosquatting, was used to deceive developers and infiltrate systems.

The Impact of the Attack

These affected packages boast around 8 million downloads weekly, significantly increasing the potential reach of the malicious code. Developers who installed any Mastra packages on June 17 are urged to check their systems for vulnerabilities.

The attackers initially took control of the ‘ehindero’ NPM maintainer account, which allowed them to inject the malicious dependency across the Mastra ecosystem. Prior to this, they had released a clean version of easy-day-js from another account, ‘sergey2016’, a day before the account takeover.

Technical Details and Mitigation Measures

The compromised packages included an obfuscated postinstall script that would retrieve a secondary payload from the attackers’ servers, executing it discreetly on targeted systems. This attack affected Windows, macOS, and Linux, masquerading as node-related tools while collecting system data and targeting cryptocurrency browser extensions.

Microsoft attributes this attack to Sapphire Sleet, a financially motivated group also known as BlueNoroff or CageyChameleon, previously linked to similar attacks such as the Axios breach. Developers are advised to remove affected package versions, sweep their systems for malware, and enhance security around their crypto-assets.

Cybersecurity entities like Aikido, Ox, Socket, and others have published insights into this breach, offering guidance on identifying and mitigating the threat. As the software industry grapples with these challenges, understanding and addressing vulnerabilities remains paramount.

Security Week News Tags:AI agents, BlueNoroff, Cryptocurrency, cyber threat, Cybersecurity, Malware, Mastra framework, Microsoft, North Korea, NPM, Sapphire Sleet, Software Security, supply chain attack, TypeScript, UNC1069

Post navigation

Previous Post: Protect AI Agents from Legacy Infrastructure Surprises
Next Post: WhatsApp Malware Targets Windows Users Globally

Related Posts

Black Hat USA 2025 – Summary of Vendor Announcements (Part 4) Black Hat USA 2025 – Summary of Vendor Announcements (Part 4) Security Week News
Cursor AI Flaw Endangers Developer Systems Cursor AI Flaw Endangers Developer Systems Security Week News
SonicWall SMA Appliances Targeted With New ‘Overstep’ Malware SonicWall SMA Appliances Targeted With New ‘Overstep’ Malware Security Week News
Casie Antalis Named Executive Director of CISA Casie Antalis Named Executive Director of CISA Security Week News
Coruna Exploit Kit Targets iOS in Global Attacks Coruna Exploit Kit Targets iOS in Global Attacks Security Week News
Apple Patches Zero-Day Exploited in Targeted Attacks Apple Patches Zero-Day Exploited in Targeted Attacks Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Fortinet Addresses FortiBleed Threat to Firewalls
  • Squid Proxy Vulnerability ‘Squidbleed’ Exposes HTTP Requests
  • QNAP Addresses Critical NAS Security Flaws
  • Critical Squid Proxy Flaw ‘Squidbleed’ Exposes User Data
  • OXLOADER Exploits Malicious Ads to Spread CastleStealer

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Fortinet Addresses FortiBleed Threat to Firewalls
  • Squid Proxy Vulnerability ‘Squidbleed’ Exposes HTTP Requests
  • QNAP Addresses Critical NAS Security Flaws
  • Critical Squid Proxy Flaw ‘Squidbleed’ Exposes User Data
  • OXLOADER Exploits Malicious Ads to Spread CastleStealer

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark