Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
North Korean Hackers Target Developers via Mastra npm

North Korean Hackers Target Developers via Mastra npm

Posted on June 22, 2026 By CWS

In a recent cybersecurity incident, North Korean hackers have exploited a popular developer tool, compromising over 140 software packages that are integral to global development processes. This sophisticated attack raises critical concerns regarding the security of open-source supply chains and the safety of developers worldwide.

Targeting the Mastra npm Ecosystem

The attack focused on the Mastra ecosystem within the npm registry, a crucial package manager for JavaScript applications. The attackers obtained access to a legitimate account, injecting malicious code into numerous packages simultaneously. This breach meant that any developer or automated system executing standard installation commands could unknowingly introduce harmful software.

Microsoft analysts discovered the breach through anomalous publishing patterns within the Mastra package. Tracing the attack back to Sapphire Sleet, a North Korean group known for financial and cryptocurrency sector assaults since 2020, they revealed the campaign’s origins.

Execution of the Malicious Campaign

The breach began with the compromise of the ehindero npm maintainer account, which had extensive publishing rights. The attackers then crafted a counterfeit package, easy-day-js, mimicking the widely-used dayjs library. This strategy expanded the attack’s reach by updating all compromised packages to include easy-day-js as a dependency.

The attack employed a two-step delivery method. Initially, a legitimate version of easy-day-js was released, followed by a weaponized version containing a hidden postinstall hook. This hook executed an obfuscated script, bypassing security checks, and connecting to hacker-controlled servers to deploy a second-stage payload.

Implications and Recommendations

The malicious code’s automatic execution upon installation posed significant threats to developer workstations, build servers, and CI/CD pipelines. On Windows systems, the implant also injected code directly into memory, evading many security measures and collecting sensitive data.

To mitigate risks, Microsoft advises developers to scrutinize their dependency trees for affected Mastra packages and to look for easy-day-js in project files. Utilizing the npm install command with the –ignore-scripts flag can prevent automatic execution of postinstall hooks. Additionally, rotating credentials and blocking malicious IP addresses are recommended measures.

This incident underscores the need for heightened vigilance in software supply chain security, particularly as attackers continue to refine their methods. Developers and organizations must adopt robust security practices to safeguard their systems against increasingly sophisticated threats.

Cyber Security News Tags:CI/CD pipelines, cyber attack, Cybersecurity, developer security, developer tools, malicious code, Mastra npm, Mastra supply chain, North Korean hackers, npm attack, Obfuscated scripts, open source security, software packages, Software Security, supply chain attack

Post navigation

Previous Post: Klue Hack Affects Multiple Cybersecurity Firms
Next Post: Canada’s Spy Agency Neutralizes Botnets with Unique Warrant

Related Posts

Critical MongoDB Flaw Exposes Servers to Attacks Critical MongoDB Flaw Exposes Servers to Attacks Cyber Security News
New Ghost Tapped Attack Uses Your Android Device to Drain Your Bank Account New Ghost Tapped Attack Uses Your Android Device to Drain Your Bank Account Cyber Security News
SideWinder Hacking Group Uses ClickOnce-Based Infection Chain to Deploy StealerBot Malware SideWinder Hacking Group Uses ClickOnce-Based Infection Chain to Deploy StealerBot Malware Cyber Security News
CISA Releases Operational Technology Guide for Owners and Operators Across all Critical Infrastructure CISA Releases Operational Technology Guide for Owners and Operators Across all Critical Infrastructure Cyber Security News
Dropping Elephant Hacker Group Attacks Defense Sector Using Python Backdoor via MSBuild Dropper Dropping Elephant Hacker Group Attacks Defense Sector Using Python Backdoor via MSBuild Dropper Cyber Security News
Ivanti ITSM Vulnerability Risks Admin Access Ivanti ITSM Vulnerability Risks Admin Access Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Models Uncover Vulnerabilities, Risk Network Security
  • Paperclip Security Flaw Risked Code Execution
  • Ransomware Operator Gets 16-Year Prison Sentence
  • Cisco Urges Immediate Update for Critical IOS XE Vulnerabilities
  • Meta AI’s Uncontrolled Cybersecurity Test Breach

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Models Uncover Vulnerabilities, Risk Network Security
  • Paperclip Security Flaw Risked Code Execution
  • Ransomware Operator Gets 16-Year Prison Sentence
  • Cisco Urges Immediate Update for Critical IOS XE Vulnerabilities
  • Meta AI’s Uncontrolled Cybersecurity Test Breach

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark