Plaintext with Rich

← Plaintext with Rich24 Jul · 10 min

North Korea Mastra NPM Supply Chain Attack: How It Works

North Korea Mastra NPM Supply Chain Attack: How It Works24 Jul10 min

You installed a dependency before lunch. Tests passed, app booted, nothing looked wrong. By dinner, your machine had quietly run someone else's code. This episode covers the Mastra npm supply chain compromise Microsoft attributed to North Korea linked threat actors. We break down how postinstall scripts became the attack vector, why an 88 minute exposure window still matters, and what remote access trojans do on developer endpoints. You will learn how AI framework supply chains expand your ...