United States
USA
Mastra reported that a maintainer was compromised through social phishing and that a token associated with the account was used on 16 June 2026 to publish 116 malicious npm packages containing a credential-exfiltrating post-install payload. All affected versions were unpublished or deprecated by 23:57 PT and safe replacements followed. Microsoft later attributed the campaign with high confidence to Sapphire Sleet.
Estimated severity
72 / 100
Source reliability
No information
Approximate Date
16/06/2026
Targeted Company
KEPLER SOFTWARE
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
United States
USA
No other affected countries reported
Target country
United States
Affected countries
Impacted regions
Duration
0.24 days
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
Incident Sources
Please rotate your phone