Security News

Cybersecurity news aggregator

⚔️
HIGH Attacks Malpedia

From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet

The Mastra npm package was compromised by the threat actor Sapphire Sleet to deliver a postinstall payload, constituting a software supply chain attack. The article does not provide specific version ranges, a CVSS score, a fixed version, or a recommended workaround.
Read Full Article →

2026-06-17 (Back to Inventory) From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet Author(s): Microsoft Defender Research Team Organization: Microsoft Open article directly Open article on Archive.org Related Articles 2026-05-18 ⋅ Microsoft ⋅ Microsoft Defender Security Research Team How Storm-2949 turned a compromised identity into a cloud-wide breach Storm-2949 2026-05-14 ⋅ Microsoft ⋅ Microsoft Threat Intelligence Kazuar: Anatomy of a nation-state botnet Kazuar 2026-04-07 ⋅ Microsoft ⋅ Microsoft Threat Intelligence SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks

Share this article