Breach404
Back to Insights
AI Security2 min readJune 20, 2026

Microsoft links Mastra AI supply chain attack to North Korean hackers

Microsoft has attributed a supply chain attack on Mastra AI that compromised over 140 npm packages to North Korean hackers from the Sapphire Sleet group, marking a significant escalation in state-sponsored threats targeting open-source software repositori

Could your website be vulnerable to attacks like this?

Run a free 10-point security scan on your site — headers, SSL, DNS, and more. Results in 15 seconds.

Test Your Site Now — It's Free