Microsoft links Mastra AI supply chain attack to North Korean hackers
What happened
Microsoft attributed a Mastra npm supply‑chain compromise to a North Korean group after attackers hijacked a maintainer account and pushed malicious updates. The attackers used a typosquat dependency that executed a post‑install hook to deploy a dropper and steal credentials and tokens; multiple @mastra‑scoped packages were affected, so watch build pipelines and registries for those names and require remediation evidence before accepting supplier invoices
Why the category manager should care
Treat package scopes and maintainers as part of your supplier surface; require provenance, signing, and the ability to block or pin packages used in production
Key facts
- Compromised maintainer account published malicious updates
- Malicious dependency used a post‑install hook to deploy a dropper
- Attack affected multiple @mastra‑scoped packages