Mastra npm org republished 140+ packages with a dropper dependency

2026-06-17 Isotope13

https://isotope13.ai/compendium/2026/mastra/

Thumbnail for Mastra npm org republished 140+ packages with a dropper dependency

Sapphire Sleet compromised a Mastra maintainer and used retained npm publishing access with an MFA token bypass to republish more than 140 `@mastra` packages with the malicious `easy-day-js` dependency. Its obfuscated post-install dropper contacted `23.254.164.92:8000` to retrieve a second stage and recorded installation paths for victim mapping before deleting itself. Microsoft assessed that the North Korean actor sought LLM API keys, cloud credentials, database connection strings, and CI/CD secrets, with cryptocurrency theft as the primary motivation. Systems that installed affected Mastra packages after June 16, 2026 were considered potentially compromised.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 23.254.164.92 2026-06-16 2026-06-24
HASH 7d5e83509ca34495c8d1869f21f3431… 2026-06-17 2026-06-17
HASH 2b4b10b2655b251c0b58a6f0a90db66… 2026-06-17 2026-06-17
HASH 8a82157e66ae712bff528bcb0aa44fb… 2026-06-17 2026-06-17
HASH 1b3af7a4f7f08f308f0550b428e2e38… 2026-06-17 2026-06-17
HASH d0d7ad6fad73678dba14c068baa52f1… 2026-06-17 2026-06-17
HASH e743f1f0583b2d14ab72777cc7f0c99… 2026-06-17 2026-06-17
HASH 0e892f51c15dd0fd1b466339dd8161a… 2026-06-17 2026-06-17
HASH 545496ca30982faf438999c56f484da… 2026-06-17 2026-06-17
URL https://23.254.164.92:8000 2026-06-17 2026-06-17

Related Actors

Related Reports

« Back