Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

North Korean state-sponsored group Sapphire Sleet (BlueNoroff) compromised a dormant contributor account in the Mastra AI npm package scope and pushed malicious updates across 140+ packages, weaponizing them to steal developer credentials, API keys, and cryptocurrency wallet data on Windows, Linux, and macOS. Any organization whose developers installed or updated @mastra-scoped npm packages on or after the compromise date is at risk of credential theft and potential lateral movement into CI/CD pipelines, cloud environments, and financial accounts. Microsoft attributed this attack with high confidence and linked it to the same actor behind the April 2026 Axios npm supply chain compromise, signaling an active, escalating campaign targeting the developer toolchain.

Author

Tech Jacks Solutions