From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet
CYBERSECURITY FEATURED ANALYSIS

From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet

BY

Microsoft Defender Security Research Team and Microsoft Threat Intelligence

SOURCE

Threat intelligence | Microsoft Security Blog

DATE

READ

1 min read

A poisoned npm package infected 140+ projects with a hidden payload. This report highlights how to detect, hunt, and defend against supply chain attacks using Microsoft Defender and actionable threat intelligence. The …

A poisoned npm package infected 140+ projects with a hidden payload. This report highlights how to detect, hunt, and defend against supply chain attacks using Microsoft Defender and actionable threat intelligence. The post From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet appeared first on Microsoft Security Blog.