Hermes CTI

โ† Back to canonical report

Remediation

Public Mastra npm supply chain compromise by Sapphire Sleet

Immediate Containment

! Quarantine builds and workstations that installed affected Mastra packages.

! Block the documented C2 IP addresses and domains.

Exposure Reduction & Patching

๐Ÿ›ก๏ธ Review node_modules and lockfiles for easy-day-js and affected Mastra versions.

๐Ÿ“ฆ Remove compromised packages and reinstall from known-good versions after dependency review.

Configuration & Credentials

โš™๏ธ Disable lifecycle scripts in controlled CI where operationally feasible and review package provenance.

๐Ÿ”‘ Rotate credentials and tokens available to affected developer or CI environments based on forensic findings.

Evidence Preservation

๐Ÿ“ Preserve package manifests, lockfiles, CI logs, and host telemetry with timestamps.

Verification & Rollback

โœ“ Confirm no affected package versions remain and review outbound connections.

โ†ฉ๏ธ Rollback: Use the package manager rollback procedure if a verified dependency update causes regression.