Mastra npm org republished 140+ packages with a dropper dependency
2026-06-17 • Isotope13 •
Sapphire Sleet compromised a Mastra maintainer and used retained npm publishing access with an MFA token bypass to republish more than 140 `@mastra` packages with the malicious `easy-day-js` dependency. Its obfuscated post-install dropper contacted `23.254.164.92:8000` to retrieve a second stage and recorded installation paths for victim mapping before deleting itself. Microsoft assessed that the North Korean actor sought LLM API keys, cloud credentials, database connection strings, and CI/CD secrets, with cryptocurrency theft as the primary motivation. Systems that installed affected Mastra packages after June 16, 2026 were considered potentially compromised.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 23.254.164.92 | 2026-06-16 | 2026-06-24 |
| HASH | 7d5e83509ca34495c8d1869f21f3431… | 2026-06-17 | 2026-06-17 |
| HASH | 2b4b10b2655b251c0b58a6f0a90db66… | 2026-06-17 | 2026-06-17 |
| HASH | 8a82157e66ae712bff528bcb0aa44fb… | 2026-06-17 | 2026-06-17 |
| HASH | 1b3af7a4f7f08f308f0550b428e2e38… | 2026-06-17 | 2026-06-17 |
| HASH | d0d7ad6fad73678dba14c068baa52f1… | 2026-06-17 | 2026-06-17 |
| HASH | e743f1f0583b2d14ab72777cc7f0c99… | 2026-06-17 | 2026-06-17 |
| HASH | 0e892f51c15dd0fd1b466339dd8161a… | 2026-06-17 | 2026-06-17 |
| HASH | 545496ca30982faf438999c56f484da… | 2026-06-17 | 2026-06-17 |
| URL | https://23.254.164.92:8000 | 2026-06-17 | 2026-06-17 |