Back to Intel

Intel Node

From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet

highdetection2026-06-18T03:43:04+00:00source excerpt
exploitationtradecraftdetectionwindows

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

A poisoned npm package infected 140+ projects with a hidden payload. This report highlights how to detect, hunt, and defend against supply chain attacks using Microsoft Defender and actionable threat intelligence. The post From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet appeared first on Microsoft Security Blog .

In this article Attack chain overview Discovery and initial indicators Dependency injection: the poisoned package. json Typosquat analysis: easy-day-js Staged delivery pattern Obfuscation and payload analysis TLS bypass to self-deletion Timeline analysis Who is Sapphire Sleet? Mitigation and protection guidance Microsoft Defender XDR detections Microsoft Security Copilot Advanced hunting Indicators of compromise (IOC) References Learn more June 19, 2026 update: Microsoft assesses with high confidence that this activity is attributable to Sapphire Sleet , a North Korean state actor that primarily targets the financial sector.

The infrastructure and post-compromise TTPs observed in this campaign are consistent with previously documented Sapphire Sleet activity.

Read Original Source