Adversary Intelligence — 2026-06-20

Microsoft Attributes Mastra AI Framework npm Supply Chain Attack to North Korean Sapphire Sleet Group

BLUFSapphire Sleet's exploitation of dormant npm contributor permissions exposes a systemic ecosystem weakness, yet DOJ indictments or OFAC sanctions tied to this campaign remain unlikely within 12 months of Microsoft's June 2026 attribution.

On June 19, Microsoft attributed a supply chain attack on 140+ Mastra AI framework npm packages to Sapphire Sleet, a North Korean state actor it also links to an April 2026 Axios npm compromise 1. The attack exploited the ehindero npm account, a dormant former contributor whose @mastra scope-wide publish rights were never revoked, to inject easy-day-js, a dayjs typosquat, as a phantom dependency across the poisoned packages 12. The malicious postinstall hook disabled TLS verification, fetched a second-stage payload from attacker-controlled servers, and installed cross-platform persistence disguised as Node tooling while collecting cryptocurrency wallet data, browser history, and credentials 12. npm removed the malicious packages and revoked attacker publish access; Mastra forward-rolled clean versions of all 142 affected publishable packages the same day 12.

Analysis
The dormant-contributor permission gap exploited here is systemic across npm: any organization running automated builds without committed lockfiles carries equivalent exposure. Microsoft Security Blog is the sole primary attribution authority, with Snyk contributing independent artifact convergence. The staged PowerShell backdoor delivered to selected targets indicates Sapphire Sleet treated this as a persistent-access campaign rather than a pure financial sweep. DOJ indictments or OFAC designations are unlikely within 12 months. Moderate confidence rests on the April 2026 Axios compromise producing no announced legal action and North Korean cyber indictments historically taking years post-attribution. An independent financially-motivated actor who cloned Axios campaign tooling would account for the TTP overlap without requiring state direction. A confirmed state nexus gives policy coordinators a legal deterrence hook for npm governance mandates; without it, the lever is pushing GitHub to enforce provenance attestation and script-blocking as opt-out defaults.
4 sources
  1. From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet - Microsoft Security Blog
  2. Mastra npm Scope Takeover: A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope - Snyk
  3. Mastra AI Framework Poisoned in npm Supply-Chain Attack - BankInfoSecurity
  4. Hackers Target npm Ecosystem by Compromising 140+ Mastra Packages - GBHackers

View in full brief →

UNCLASSIFIED // OPEN SOURCE