Microsoft has attributed a supply chain attack on the Mastra AI npm ecosystem to North Korean state-sponsored group Sapphire Sleet (BlueNoroff). Attackers compromised the npm maintainer account 'ehindero' and published malicious updates to over 140 packages in the @mastra scope, injecting a typosquatted dependency called 'easy-day-js' (mimicking dayjs). A post-install hook deployed a cross-platform information stealer targeting Windows, Linux, and macOS, collecting browser history, credentials, API keys, and checking for 166 cryptocurrency wallet extensions including MetaMask and Coinbase Wallet. The malware used OS-specific persistence mechanisms and connected to attacker-controlled C2 infrastructure. Microsoft also linked the same group to a prior npm supply chain attack on the Axios HTTP client in April 2026.

3m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Cross-platform malware targets crypto walletsTest every layer before attackers do
1.2K Impressions