Microsoft links Mastra AI npm supply chain attack to North Korea’s Sapphire Sleet

Microsoft ties npm compromise to North Korean group
Microsoft has attributed a recent supply chain attack targeting the Mastra AI package ecosystem to Sapphire Sleet, a North Korean hacking group also tracked as BlueNoroff. The company said the campaign compromised more than 140 npm packages after attackers hijacked a maintainer account and pushed malicious updates into the widely used JavaScript registry.
In a June 19 update, Microsoft said it had “high confidence” the activity was linked to Sapphire Sleet, describing the group as a North Korean state actor that primarily targets the financial sector.
The attack began with the compromise of the npm maintainer account “ehindero,” which had publishing access across the Mastra package environment. From there, the attackers inserted a malicious dependency called “easy-day-js” into more than 140 packages in the @mastra scope. The name was a typosquat of the legitimate dayjs library, a common trick meant to blend in with trusted software.
Malicious install chain hit developers’ devices
Once installed, the fake dependency triggered a post-install hook that dropped malware onto developers’ systems. Microsoft said the payload was aimed at stealing sensitive credentials, API keys, authentication tokens and cryptocurrency wallets.
The company said the code disabled TLS certificate verification, reached out to attacker-controlled command-and-control infrastructure, downloaded a second-stage payload and ran it as a detached hidden process. That second-stage payload was a cross-platform information stealer built to run on Windows, Linux and macOS.
Microsoft said the implant gathered host details, browser history, installed applications and running processes. It also checked for 166 cryptocurrency wallet browser extensions, including MetaMask, Phantom, Coinbase Wallet, Binance Wallet and TronLink.
Persistence methods varied by operating system, with the malware using Windows Registry Run keys, macOS LaunchAgents and Linux systemd services.
Microsoft also said systems that contacted the attackers’ servers later showed activity consistent with Sapphire Sleet’s previous operations, including a PowerShell backdoor, additional persistence mechanisms, Microsoft Defender exclusions and a malicious Windows service that granted SYSTEM privileges.
“The PowerShell backdoor, tradecraft, and C2 infrastructure have been used by Sapphire Sleet in other, prior campaigns,” Microsoft said.
Sapphire Sleet has previously been associated with cryptocurrency theft, malicious browser extensions, fake job offers and software supply chain attacks designed to steal credentials and crypto assets.
Sources:
Read more tech news on the Doppler VPN Blog.