North Korea-Linked Attackers Poison 131 Mastra AI Packages
CrowdStrike reports that North Korea-linked adversaries used stolen credentials to inject malicious dependencies into over 130 Mastra AI framework packages on the npm registry.
CrowdStrike Holdings, Inc. reported on August 3 that a North Korea-linked adversary poisoned at least 131 Mastra AI framework packages on the npm registry. The attacker utilized stolen maintainer credentials to publish versions containing a malicious dependency called 'easy-day-js'. This specific injection allows for remote code execution and the theft of credentials from developer machines and build pipelines.
CrowdStrike noted that npm packages were the primary target for software-registry threats in the first half of 2026, accounting for 87% of all identified cases. This trend aligns with a broader pattern of supply chain attacks targeting developer environments.
Microsoft Corporation, the owner of the npm registry and GitHub, previously conducted an investigation on June 17. During that probe, Microsoft identified over 140 affected packages and detailed detections through its Defender security suite. The findings confirm a coordinated effort by state-linked actors to compromise AI framework dependencies to gain unauthorized access to corporate and individual infrastructure.