131 Poisoned AI Packages Hit Microsoft’s (MSFT) npm.
CrowdStrike (CRWD) Couldn’t Ask for a Better Sales Pitch CrowdStrike Holdings, Inc. (NASDAQ:CRWD) said on August 3 that a North Korea-linked adversary injected a malicious dependency into at least 131 Mastra AI framework packages on npm (Node Package Manager)
Microsoft Corporation (NASDAQ:MSFT) owns GitHub, which acquired npm in 2020 and operates the registry at the center of the attack chain. This was a developer-supply-chain breach with unusually efficient distribution. Stolen maintainer credentials let the attacker publish poisoned Mastra versions tagged as the latest releases.
The malicious easy-day-js dependency then ran during installation, exposing developer machines and build pipelines to credential theft and remote code execution. CrowdStrike found that 87% of identified software-registry threats in the first half of 2026 involved npm packages. Image by Tawanda Razika from Pixabay Microsoft’s role cuts both ways.