Mark RadarMARK RADAR
About
EN
Sign in

North Korean Hackers Hit AI Framework Mastra in Supply-Chain Attack

2 reports · First detected 2026-06-22 · Last active 2026-06-22

Mastra is an open-source framework for building AI applications and agent systems, with developers integrating its features through NPM packages. The incident began when North Korean hacking group BlueNoroff stole a developer’s account and used its legitimate publishing privileges to distribute a backdoor, highlighting risks to open-source software supply chains and account security.

Cybersecurity reports published on June 22 said more than 140 Mastra NPM packages had been injected with the malicious easy-day-js dependency. Compromised versions disabled TLS certificate verification and connected to the attackers’ command-and-control servers. After Microsoft reported the anomalous activity, NPM removed all affected packages, reducing the risk of further downloads and propagation.

All Coverage

2 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)