Historical intelligence backfill. This assessment covers reporting originally published on 2026-06-17 and was added to the RWP archive on 2026-09-07.
Sapphire Sleet poisoned @mastra in 45 minutes — easy-day-js was the dropper, npm was the plant
17 June 2026 — 140+ packages, postinstall, TLS verify off, second-stage crypto-stealer. Microsoft high confidence: same DPRK cluster as Axios. Maintainer phished on a call.
Bottom line up front
CONFIRMED 17 June 2026 attackers used a compromised Mastra maintainer npm account (ehindero) to republish 140+ packages in the @mastra / mastra / create-mastra scopes with a new dependency easy-day-js (dayjs typosquat). easy-day-js@1.11.22 postinstall disabled TLS verification, fetched a second stage from a raw IP, ran a hidden cross-platform stealer aimed at 160+ crypto extensions plus host/CI secrets. Window: ~01:12–02:36 UTC 17 June for the bulk republish (Snyk); project incident report: 6:12–6:37 PM PT, awareness 8:45 PM PT, unpublished/deprecated by 11:57 PM, clean versions ~1 AM. Microsoft 19 June update: high confidence Sapphire Sleet (BlueNoroff / CageyChameleon / Copernicium / Stardust Chollima) — same cluster as the April Axios npm hit already in this archive. Root cause in Mastra's own write-up: maintainer machine phished via LinkedIn + a call (same pattern other TS maintainers reported). Poison was at publish time, not in git. Anyone who npm installed @mastra during the window: treat as compromised.
Historical backfill of 17 June 2026 reporting; added 7 September 2026.
What happened
DPRK-aligned crimeware used an AI-agent framework's npm org as the distribution channel. Scope permissions outlived the contributor relationship.
Why it mattered
CI runners and developer laptops are production. A 45-minute window at 8 million weekly downloads is a lot of postinstall.
Who / what was affected
Installers of poisoned versions (@mastra/core@1.42.1, mastra@1.13.1, etc.). Crypto wallets and build secrets.
Technical context
Pin versions. Disable lifecycle scripts in CI where you can. Revoke npm tokens. Rotate everything that touched those machines.
Exploitation / threat status at the time
CONFIRMED Microsoft + Snyk + project incident.
REPORTED Sapphire Sleet attribution (high confidence Microsoft).
What defenders should have done
- Lockfile + ignore-scripts in CI.
- npm 2FA and least-privilege publish.
- Incident: reimage, rotate cloud keys, hunt the dropper.
RWP assessment
Confidence: High. Pair with Axios — two Sapphire Sleet npm hits in one quarter.
Defensive actions
- Audit
@mastrainstalls on 17 June. - Block
easy-day-js. - Maintainer phishing is the control, not YARA after the fact.
Sources
- Microsoft Security — Mastra npm compromise by Sapphire Sleet
- Snyk — Forgotten contributor account / @mastra scope takeover
- mastra-ai/mastra — Incident report issue #18061