Skip to content
Registry/APM-0079
APM-00794SEVEREReported June 17, 2026

North Korea's Sapphire Sleet poisoned 145 Mastra AI agent packages on npm within 19 minutes of weaponization

Agent Involved
Mastra
Estimated Damage
Not quantified
Severity
4 / 5 Severe
Impact Band
Serious damage. Customer data affected, security incident, or financial losses $10k–$100k.

Independent project · aggregated from public reports and may be unverified — see the primary source below · not affiliated with or endorsed by any company or product named.

On 17 June 2026, 145 packages in the @mastra/* namespace, the AI agent framework whose @mastra/core alone draws over 918,000 weekly npm downloads, were republished with a malicious transitive dependency named easy-day-js, a typosquat of dayjs. A clean bait version was published the previous day; the weaponized version landed at 01:01 UTC and more than 140 Mastra packages were republished by 01:20 UTC. A postinstall hook ran an obfuscated dropper that disabled TLS certificate verification, pulled a roughly 41 KB Node.js implant, harvested cryptocurrency wallet data, browser history and host reconnaissance, and installed persistence on Windows, macOS and Linux plus a PowerShell backdoor for SYSTEM-context access. Microsoft attributed the campaign to the North Korean group Sapphire Sleet, with the root cause being social engineering of an active Mastra employee's npm account.

Verified Facts

  • 145 @mastra/* packages were republished with a malicious easy-day-js dependency on 17 June 2026
  • More than 140 packages were republished within roughly 19 minutes of weaponization
  • Microsoft attributed the campaign to the North Korean actor Sapphire Sleet

Not Publicly Confirmed

  • How many downstream developers installed the malicious versions
  • The total value of cryptocurrency stolen

Operational Lessons

  • AI agent frameworks are first-class supply chain targets because they run on developer machines holding wallets and cloud credentials
  • Account trust is not enough for publishing; provenance and trusted-publisher enforcement are needed
From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet (Microsoft Security Blog)microsoft.com
Case No.
APM-0079
Reported
June 17, 2026
Attribution
Anonymous
Discussion

More Cases

0
APM-0083Cursor3MODERATE
Jan 14, 2026

Cursor's command allowlist could be bypassed with shell built-ins, giving prompt injection a silent path to code execution

Pillar Security disclosed CVE-2026-22708 in Cursor. In Auto-Run Mode with an allowlist enabled, shell built-ins such as export, typeset, declare, readonly, unset and local were implicitly trusted by Cursor's server-side evaluator and executed without appearing in the allowlist or requiring approval, because they run inside the shell session rather than as separate binaries. An attacker delivering indirect prompt injection could silently poison environment variables and then trigger malicious code through trusted developer tools, producing both zero-click and one-click remote code execution. Pillar reported it in August 2025, Cursor acknowledged it as a systemic issue in September 2025, and the fix shipped in version 2.3 in January 2026, which now requires explicit approval for any command the parser cannot classify.

0
May 7, 2026

Prompt injection reached host-level code execution in Microsoft Semantic Kernel through eval() and a stray annotation

Microsoft disclosed two vulnerabilities that turn prompt injection into host compromise in its Semantic Kernel agent framework, which has over 27,000 GitHub stars. CVE-2026-26030 affects the Python package before 1.39.4: the default in-memory vector store filter is a Python lambda executed with eval() on unsanitized model-controlled input, so an attacker could escape the template string, traverse Python's class hierarchy, bypass the AST blocklist validator and run arbitrary commands, demonstrated by launching calc.exe from a single prompt injection. CVE-2026-25592 affects the .NET SDK before 1.71.0: DownloadFileAsync was accidentally marked with a [KernelFunction] attribute, exposing it to the model with an entirely AI-controlled, unvalidated local file path, allowing writes to locations such as the Windows Startup folder and thus sandbox escape.

0
APM-0080Microsoft 365 Copilot4SEVERE
Jun 15, 2026

SearchLeak let a single click on a malicious link pull emails, files and MFA codes out of Microsoft 365 Copilot

Varonis Threat Labs disclosed CVE-2026-42824, a critical flaw in Microsoft 365 Copilot Enterprise Search. Clicking a single crafted link chained three bugs: injection of the URL parameter into the prompt, a rendering race condition, and abuse of Content Security Policy allowlisting to exfiltrate data through Bing's infrastructure. The attack could reach emails and calendar details, indexed SharePoint and OneDrive files, one-time and MFA codes, password-reset links, meeting notes and salary data. Because Copilot Enterprise is a managed service, tenant admins could not patch it themselves; Microsoft mitigated the flaw on its backend.