Microsoft Pins Mastra AI npm Supply Chain Attack on North Korea's Sapphire Sleet
North Korea is attacking the AI developer supply chain. Not metaphorically — literally. Microsoft Threat Intelligence has formally attributed the June 17, 2026 npm supply chain attack against the Mastra AI framework to Sapphire Sleet, the North Korean state-sponsored group also tracked as BlueNoroff and historically linked to the Lazarus Group umbrella. This is one of the most significant nation-state intrusions into the AI tooling ecosystem to date. Over 140 Mastra packages were compromised. The attack was completed in approximately 88 minutes. And any developer, CI/CD pipeline, or build system that installed or updated affected packages during the window is potentially compromised. ...