Hermes CTI

← Back to canonical report

Detections

Public Mastra npm supply chain compromise by Sapphire Sleet

Mastra npm postinstall payload behavior

sigma · generated; parse required before publication
title: Mastra npm postinstall payload behavior
description: Detects Node.js execution of the documented malicious package installation
  artifacts.
logsource:
  product: windows
detection:
  selection:
    process.command_line: setup.cjs
  condition: selection
level: medium
tags: []
references: []