Public Mastra npm supply chain compromise by Sapphire Sleet
Executive summary
The observed chain began with npm maintainer-account takeover and dependency injection. easy-day-js 1.11.22 executed setup.cjs during npm installation, disabled TLS verification, contacted 23.254.164.92 and 23.254.164.123, fetched second-stage JavaScript, and established cross-platform persistence. Microsoft attributed the activity to Sapphire Sleet with high confidence.
Technical analysis
The observed chain began with npm maintainer-account takeover and dependency injection. easy-day-js 1.11.22 executed setup.cjs during npm installation, disabled TLS verification, contacted 23.254.164.92 and 23.254.164.123, fetched second-stage JavaScript, and established cross-platform persistence. Microsoft attributed the activity to Sapphire Sleet with high confidence.
Evidence and sources
Microsoft Threat Intelligence reported a Mastra npm supply chain compromise by Sapphire Sleet affecting 140+ packages, a malicious easy-day-js postinstall payload, command-and-control infrastructure, persistence, and PowerShell backdoor activity.
Microsoft Threat Intelligence reported a Mastra npm supply chain compromise by Sapphire Sleet affecting 140+ packages, a malicious easy-day-js postinstall payload, command-and-control infrastructure, persistence, and PowerShell backdoor activity.
IOCs
teams.onweblive.org
maskasd.com
23.254.164.92
23.254.164.123
b122a9873bedf145ae2a7fd024b5f309007dbb025149f4dc4ac3f7e4f32a36a4
ae70dd4f6bc0d1c8c2848e4e6b51934626c4818dcb5af99d080ddbd7dc337185
50eae63d3e24be9ca8803f4b5a0408aef97ee3fab7af018d8c2dde7c359edd65
CVEs and affected products
No CVE or affected product is available.
ATT&CK mapping
No ATT&CK mapping is available.
Detection content
Sigma rules, YARA rules, Splunk SPL, and KQL detection logic.
Threat hunting
Hypothesis-driven hunt procedures and telemetry checklist.
Remediation
Containment actions, patching notes, and credential steps.
Historical relationships
No published historical relationship is available.
Timeline and change history
Confidence and caveats
0.9
⚠️ This report covers public technology and threat reporting only; it does not assess organizational exposure.