supply-chain
Microsoft links Mastra AI supply chain attack to North Korean hackers
High
Summary
Microsoft has attributed a recent supply chain attack targeting over 140 npm packages to the North Korean hacking group Sapphire Sleet, also known as BlueNoroff. The attack involved compromising an npm maintainer account to inject a malicious dependency, ‘easy-day-js,’ which deployed a cross-platform information stealer designed to steal credentials and cryptocurrency wallet data. This incident highlights the ongoing risks associated with software supply chain vulnerabilities and the tactics employed by state-sponsored actors.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data