Hermes CTI

← Back to all reports

threat_event updated

Public Mastra npm supply chain compromise by Sapphire Sleet

● HIGH Confidence: 90% · Version 2

Executive summary

The observed chain began with npm maintainer-account takeover and dependency injection. easy-day-js 1.11.22 executed setup.cjs during npm installation, disabled TLS verification, contacted 23.254.164.92 and 23.254.164.123, fetched second-stage JavaScript, and established cross-platform persistence. Microsoft attributed the activity to Sapphire Sleet with high confidence.

Technical analysis

The observed chain began with npm maintainer-account takeover and dependency injection. easy-day-js 1.11.22 executed setup.cjs during npm installation, disabled TLS verification, contacted 23.254.164.92 and 23.254.164.123, fetched second-stage JavaScript, and established cross-platform persistence. Microsoft attributed the activity to Sapphire Sleet with high confidence.

Evidence and sources

Microsoft Threat Intelligence reported a Mastra npm supply chain compromise by Sapphire Sleet affecting 140+ packages, a malicious easy-day-js postinstall payload, command-and-control infrastructure, persistence, and PowerShell backdoor activity.

Verified Evidence Claims

Microsoft Threat Intelligence reported a Mastra npm supply chain compromise by Sapphire Sleet affecting 140+ packages, a malicious easy-day-js postinstall payload, command-and-control infrastructure, persistence, and PowerShell backdoor activity.

95% Confidence Analysis 🔍

IOCs

CVEs and affected products

No CVE or affected product is available.

ATT&CK mapping

No ATT&CK mapping is available.

Detection content

Sigma rules, YARA rules, Splunk SPL, and KQL detection logic.

Open dedicated detections page →

Threat hunting

Hypothesis-driven hunt procedures and telemetry checklist.

Open dedicated hunt page →

Remediation

Containment actions, patching notes, and credential steps.

Open dedicated remediation page →

Historical relationships

No published historical relationship is available.

Timeline and change history

Public report: Microsoft Threat Intelligence reported a Mastra npm supply chain compromise by Sapphire Sleet affecting 140+ packages, a malicious easy-day-js postinstall payload, command-and-control infrastructure, persistence, and PowerShell backdoor activity.

Confidence and caveats

0.9

⚠️ This report covers public technology and threat reporting only; it does not assess organizational exposure.