Observed Signal · Jun 20, 2026 · Supply Chain Attack · Source: DEV Community · Impact: 4/5 · Sentiment: Negative

North Korean Hackers Poisoned 140+ npm Packages

Executive Signal Summary

Microsoft attributed a supply-chain attack on the Mastra AI ecosystem to Sapphire Sleet (also tracked as BlueNoroff), in which attackers poisoned over 140 npm packages that AI coding assistants and developer tooling actively surface. The incident is notable because LLM-backed IDE assistants (e.g., Copilot, Cursor) can suggest or auto-install dependencies, allowing malicious code to reach developer machines without traditional phishing. Microsoft’s public details are limited: a state-level actor, 140+ contaminated packages, and a focus on AI-assisted development workflows. The article highlights detection gaps—npm audit relies on published CVEs, lockfiles help only post-install, and LLMs do not validate package provenance—and describes Sentinel’s SlopScan integration as a defensive pattern that extracts package names from LLM output and flags or blocks suspicious packages before installation. Publication date: 2026-06-20.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

A state-sponsored supply-chain compromise targeting AI-assisted developer tooling creates a new, high-risk vector that can rapidly propagate malicious code across developer environments and CI pipelines; defenses and scanning patterns described have cross-industry relevance.

SIGNAL RADAR

Track Microsoft Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Microsoft attributed a Mastra AI supply-chain attack to Sapphire Sleet (also tracked as BlueNoroff).
  • Attackers compromised over 140 npm packages in the Mastra AI dependency graph.
  • AI coding assistants (e.g., Copilot, Cursor) can suggest or auto-install dependencies, enabling the attack vector.
  • Standard tools like npm audit may not detect freshly poisoned packages because they lack published CVEs.
  • Sentinel’s SlopScan integration can extract package names from LLM output and return package_scan results (SUSPICIOUS or DANGEROUS) to flag or block installs.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: DEV Community•Published: Jun 20, 2026
Original Coverage Title: “North Korean Hackers Poisoned 140+ npm Packages in an AI Dev Tooling Attack. Here's What Would Have Caught It.”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Supply-Chain SecurityJun 9, 2026

Microsoft npm Packages Backdoored; AI Agents Trigger Credential Stealer

Seventy-three cryptographically signed Microsoft npm packages were compromised with a credential‑stealing worm called “Miasma,” derived from an open-source toolkit. The malware deploys a small (≈28 KB) payload that automatically harvests credentials from cloud providers (AWS, Azure, GCP), Kubernetes, many developer tool configs and password managers, and then spreads laterally through cloud infrastructure. The payload is triggered simply by opening a package inside AI coding agents and IDE integrations (examples named: Claude Code, Gemini CLI, Cursor, VS Code). Attackers used stolen Microsoft publisher credentials to publish malicious builds that carried valid SLSA provenance attestations, defeating provenance-only detection. The same Microsoft account had previously been compromised in May 2026 (durabletask Python SDK on PyPI), raising concerns about credential rotation and remediation.

Read assessment
Security / Software Supply ChainJun 17, 2026

144 Mastra npm Packages Compromised in Supply-Chain Attack

In June 2026, attackers hijacked an npm contributor account (ehindero) and mass-published malicious versions of 144 packages in the @mastra namespace in an incident dubbed the easy-day-js supply-chain attack. Security researchers from JFrog, SafeDep, Socket and StepSecurity jointly uncovered the breach. Mastra is a popular open-source JavaScript/TypeScript framework used for AI application development, so the compromise risks propagating malicious code into many downstream projects and AI workloads. Researchers recommend immediate automated dependency audits, removal or rollback of affected packages, credential rotation, enforcing multi-factor authentication for publishers, and continuous monitoring via supply-chain scanning tools (e.g., JFrog Xray, Socket, SafeDep). The incident underscores account-level contributor access as a major attack surface for npm and similar registries, and calls for stronger registry-level publisher controls and provenance checks.

Read assessment
Supply chain securityMay 19, 2026

Supply-chain attack compromises dozens of open-source packages

Cybersecurity researchers reported a large ongoing supply-chain attack that has compromised hundreds of open-source package versions across dozens of projects. StepSecurity and SafeDep warned that attackers hijacked a developer account and pushed more than 630 malicious versions spanning 317 npm packages in roughly 20 minutes. The malicious updates aim to harvest credentials — including from password managers — and to propagate further. Affected projects include Antv (a library associated with Alibaba); JFrog Security said some malicious updates were published via GitHub. Researchers call the campaign “Mini Shai-Hulud”; it follows an earlier wave that compromised the TanStack library and led to the computers of two OpenAI employees being breached. The incident underscores ongoing risks in open-source dependency security and rapid downstream exposure for developers and organizations that consume compromised packages.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.