CRITICAL ⚡ MUST-KNOW
North Korean Hackers Blamed for Mastra NPM Supply Chain Attack
Researchers have attributed a supply chain attack on the Mastra npm package ecosystem to North Korean threat actors. The attackers added a malicious dependency to more than 140 Mastra packages that fetches a payload designed to target cryptocurrency browser extensions. Mastra is used in AI agent development, putting downstream projects that pulled the compromised packages at risk of credential and wallet theft. Developers who installed affected Mastra packages should audit their dependency trees and rotate any exposed crypto wallet credentials.