CrowdStrike: North Korean hackers injected 131 malicious AI packages into Microsoft npm
2026-08-04 20:43:42
According to CoinMeta, on August 3, CRWD (Nasdaq: CRWD) reported that North Korean-related actors injected 131 malicious dependency packages into Microsoft's npm ( Node Package Manager ). This attack on the developer supply chain utilized stolen administrator credentials to release malicious Mastra packages. CrowdStrike found that 87% of the software registry threats identified in the first half of 2026 involved npm packages. Microsoft's GitHub controls the registry infrastructure, and its advisory database supports npm auditing; however, repeated account takeovers increased the burden on strengthening release and dependency scanning. In a survey on June 17, Microsoft discovered over 140 affected Mastra packages and conducted detections in the Defender series of products. This incident posed a reputational risk to npm but also provided Microsoft with a reason to sell integrated security solutions.
Bullish 0
Bearish 0
Source:Internet
This content is for market information only and does not constitute investment advice.