North Korean Sapphire Sleet targets npm ecosystem with Mastra AI supply chain compromise affecting 140+ packages
Microsoft attributed a compromise of over 140 npm packages to North Korean threat actor Sapphire Sleet, leveraging the Mastra AI project as an entry point. This represents a high-impact supply chain attack with potential for widespread malware distribution across the JavaScript ecosystem.