MIT TRACE

MIT CTL Logo
Back to Main Dashboard

Mastra npm supply-chain compromise distributes malicious packages

Mastra reported that a maintainer was compromised through social phishing and that a token associated with the account was used on 16 June 2026 to publish 116 malicious npm packages containing a credential-exfiltrating post-install payload. All affected versions were unpublished or deprecated by 23:57 PT and safe replacements followed. Microsoft later attributed the campaign with high confidence to Sapphire Sleet.

72

Estimated severity

72 / 100

—

Source reliability

No information

Approximate Date

16/06/2026

Targeted Company

KEPLER SOFTWARE

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

United States

USA

Other Affected Countries

No other affected countries reported

Target country

United States

Affected countries

United States

Impacted regions

California · United States

Operational Impact

Duration

0.24 days

Financial impact (USD M)

No information

Impact types

Supply chain data integrity impact

Affected sectors

Technology & IT Services

Affected departments

Engineering & MaintenanceInformation Technology

Attack Profile

Attack types

Use of stolen credentialsSoftware supply chain compromise

Attributed threat actors

SAPPHIRE SLEET

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.