Historical intelligence backfill. This assessment covers reporting originally published on 2026-06-17 and was added to the RWP archive on 2026-09-07.

Daily Top · IT

Sapphire Sleet poisoned @mastra in 45 minutes — easy-day-js was the dropper, npm was the plant

17 June 2026 — 140+ packages, postinstall, TLS verify off, second-stage crypto-stealer. Microsoft high confidence: same DPRK cluster as Axios. Maintainer phished on a call.

RWP Ventures · 2026-09-07 · event 2026-06-17 · 2 min read · priority 8.5

Bottom line up front

CONFIRMED 17 June 2026 attackers used a compromised Mastra maintainer npm account (ehindero) to republish 140+ packages in the @mastra / mastra / create-mastra scopes with a new dependency easy-day-js (dayjs typosquat). easy-day-js@1.11.22 postinstall disabled TLS verification, fetched a second stage from a raw IP, ran a hidden cross-platform stealer aimed at 160+ crypto extensions plus host/CI secrets. Window: ~01:12–02:36 UTC 17 June for the bulk republish (Snyk); project incident report: 6:12–6:37 PM PT, awareness 8:45 PM PT, unpublished/deprecated by 11:57 PM, clean versions ~1 AM. Microsoft 19 June update: high confidence Sapphire Sleet (BlueNoroff / CageyChameleon / Copernicium / Stardust Chollima) — same cluster as the April Axios npm hit already in this archive. Root cause in Mastra's own write-up: maintainer machine phished via LinkedIn + a call (same pattern other TS maintainers reported). Poison was at publish time, not in git. Anyone who npm installed @mastra during the window: treat as compromised.

Historical backfill of 17 June 2026 reporting; added 7 September 2026.

What happened

DPRK-aligned crimeware used an AI-agent framework's npm org as the distribution channel. Scope permissions outlived the contributor relationship.

Why it mattered

CI runners and developer laptops are production. A 45-minute window at 8 million weekly downloads is a lot of postinstall.

Who / what was affected

Installers of poisoned versions (@mastra/core@1.42.1, mastra@1.13.1, etc.). Crypto wallets and build secrets.

Technical context

Pin versions. Disable lifecycle scripts in CI where you can. Revoke npm tokens. Rotate everything that touched those machines.

Exploitation / threat status at the time

CONFIRMED Microsoft + Snyk + project incident.

REPORTED Sapphire Sleet attribution (high confidence Microsoft).

What defenders should have done

  1. Lockfile + ignore-scripts in CI.
  2. npm 2FA and least-privilege publish.
  3. Incident: reimage, rotate cloud keys, hunt the dropper.

RWP assessment

Confidence: High. Pair with Axios — two Sapphire Sleet npm hits in one quarter.

Defensive actions

  1. Audit @mastra installs on 17 June.
  2. Block easy-day-js.
  3. Maintainer phishing is the control, not YARA after the fact.

Sources

  1. Microsoft Security — Mastra npm compromise by Sapphire Sleet
  2. Snyk — Forgotten contributor account / @mastra scope takeover
  3. mastra-ai/mastra — Incident report issue #18061