Hermes CTI

← Back to canonical report

Hunt

Public Mastra npm supply chain compromise by Sapphire Sleet

Hunt Strategy & Objective

Identify documented endpoint, identity, network, persistence, and supply-chain behaviors without asserting internal exposure.

⏱️ Lookback: 30 days with a 24-hour baseline comparison

Hunt Hypothesis

If the documented activity is present, hosts will show: powershell; npm; javascript; postinstall.

Target Platforms & Environment

Windows Linux macOS CI/CD where applicable

Public-technology hunting guidance for environments using the affected technology or observing the documented campaign/tooling.

Required Telemetry & Data Sources

EDR process and network telemetry authentication and remote-service logs DNS/proxy or flow logs script and file telemetry

Operational Execution Phases

4 Structured Investigation Phases
1

Baseline & Telemetry Scoping

EDR process/network Sysmon Event 1/3 Security 4624/4688/4698/7045 PowerShell 4104 DNS/proxy/flow

🎯 Phase Goal: Confirm coverage and establish normal activity.

Procedural Actions

  1. 1.1 Verify process, authentication, script, DNS, proxy, and flow telemetry.
  2. 1.2 Measure normal volume by host, account, parent, destination, and admin window.
  3. 1.3 Record gaps and select benign comparison hosts.

Anomaly Confirmation & Pivot Guidance

Pivot from process to parent, child, account, hash, host, and destination.

2

Hypothesis Validation & Behavioral Sweep

EDR process/network Sysmon Event 1/3 Security 4624/4688/4698/7045 PowerShell 4104 DNS/proxy/flow

🎯 Phase Goal: Test the documented execution chain or tradecraft.

Procedural Actions

  1. 2.1 Run the typed queries for: powershell; npm; javascript; postinstall.
  2. 2.2 Review anomalous arguments, writable paths, rare parent-child pairs, and first-seen destinations.
  3. 2.3 Correlate process starts with authentication, DNS, and outbound connections.

Phase Hunting Logic & Queries

kql Behavioral sweep
DeviceProcessEvents | where Timestamp >= ago(30d) | where ProcessCommandLine has_any ('powershell', 'npm', 'javascript', 'postinstall') | project Timestamp,DeviceName,AccountName,FileName,ProcessCommandLine,InitiatingProcessFileName,SHA1 | order by Timestamp desc
💡 Tuning & Baselines: Establish a 24-hour baseline; exclude approved deployment and signed updater paths only after publisher, path, hash, and change-window validation.
sigma Process creation behavioral match
title: Public Mastra npm supply chain compromise by Sapphire Sleet - suspicious execution
logsource:
  category: process_creation
detection:
  selection:
    CommandLine|contains:
      - powershell
      - npm
      - javascript
      - postinstall
  condition: selection
level: medium
💡 Tuning & Baselines: Prioritize user-writable paths, encoded or hidden arguments, rare parent-child pairs, and first-seen accounts; suppress by verified signer and full path, never filename alone.

Anomaly Confirmation & Pivot Guidance

Pivot from process to parent, child, account, hash, host, and destination.

3

Triage & False-Positive Elimination

EDR process/network Sysmon Event 1/3 Security 4624/4688/4698/7045 PowerShell 4104 DNS/proxy/flow

🎯 Phase Goal: Separate malicious behavior from administration and maintenance.

Procedural Actions

  1. 3.1 Validate signer, install path, package provenance, and hash against inventory.
  2. 3.2 Compare frequency, timing, parent, and destination with benign baseline.
  3. 3.3 Retain matches with corroboration or unexplained deviation.

Anomaly Confirmation & Pivot Guidance

Pivot from process to parent, child, account, hash, host, and destination.

4

Scope Expansion & Evidence Preservation

EDR process/network Sysmon Event 1/3 Security 4624/4688/4698/7045 PowerShell 4104 DNS/proxy/flow

🎯 Phase Goal: Determine blast radius and preserve evidence.

Procedural Actions

  1. 4.1 Search lateral movement, persistence, credential access, and repeated beaconing.
  2. 4.2 Expand across hashes, versions, scheduled tasks, services, logons, and destinations.
  3. 4.3 Preserve responder artifacts and hand off a scoped timeline.

Anomaly Confirmation & Pivot Guidance

Pivot from process to parent, child, account, hash, host, and destination.

True Positive Confirmation Evidence

Process, authentication, network, or persistence observations consistent with powershell; npm; javascript; postinstall
!

Benign & False Positive Explanations

Approved deployment and package updates
Legitimate administrator remote management
Security scanners and tooling with verified signer, path, and destination

🔬 Forensic Artifacts to Collect & Preserve

Prefetch, Amcache, ShimCache, MFT, and USN Journal
PowerShell 4104 and transcript logs
Sysmon 1/3/10/11 and Security 4624/4688/4698/7045
DNS, proxy, firewall, Zeek flow records, and TLS metadata
Memory capture and process list for live payloads
CI/package lockfiles and installer logs where applicable

Validation Checklist

Confirm UTC timestamps and host/account identity.
Validate signer, hash, package/version, and parent-child chain.
Correlate network destinations and authentication events.
Preserve artifacts and evidence IDs before containment.

Escalation Criteria

Independent telemetry corroborates the behavior.
Execution uses an unexpected or user-writable path.
A rare chain is followed by persistence, credential access, lateral movement, or unexplained external traffic.

Traceability & Related Detections