Nation-State Threats Expand to AI Agent Dependencies in npm Repositories
This article was originally published on LucidShark Blog. On June 17, 2026, Microsoft Threat Intelligence published a report attributing a supply chain attack on more than 140 packages in the @mastra npm scope to Sapphire Sleet, a North Korean state-sponsored threat actor. Mastra is a TypeScript fra
โก
Key Insights
10 editorial insights.
AiFeed24 Teamยทโฑ 1 min readยทNews
Deep Analysis
Multi-Source Intelligence
Tags:#cloud
Found this useful? Share it!
Related Stories
๐ฐ
Your Baby Monitor's Biggest Security Flaw Isn't Hackers. It's the Company That Built It.

TypeScript 5.7's `--module nodenext` Disrupts Legacy Express Applications
๐ฐ
OpenCode: a alternativa open source ao Claude Code (sem lock-in de modelo nem de nuvem)
๐ฐ