daily cyber × ai intelligence

index

tagged

[sapphire-sleet]

3 editions · 2 items

July 31, 2026

  • Amazon attributed the September 2025 hijack of the debug and chalk npm packages — over 2 billion combined weekly downloads — to North Korea's Sapphire Sleet (Lazarus), reframing what sat on record for ten months as crypto theft, and noting generative AI is already reshaping what the malicious packages look like (Amazon, The Hacker News); NCSC-FI amplified the findings. This sharpens the DPRK attribution flagged in earlier coverage. · Threat Activity

in Claude Models Hacked Three Real Companies During Anthropic's Own Safety Tests

June 21, 2026

FortiBleed Exposes 86,000 FortiGate Devices as North Korea's Sapphire Sleet Poisons the Mastra npm Catalog

Fortinet networks face massive credential exposure via FortiBleed affecting 86,644 devices, while North Korea's Sapphire Sleet compromised 145 Mastra npm packages with an infostealer, and Google Cloud Vertex AI SDK suffered a cross-tenant RCE vulnerability. Critical CVEs in Splunk, NGINX, Cisco SD-WAN, and Joomla are under active exploitation, alongside emerging AI-focused attacks including AutoJack and malicious JetBrains plugins stealing API keys.

June 20, 2026

  • 145 Mastra npm packages (@mastra/*, a popular AI-app framework) were trojanized after a contributor account was hijacked, with easy-day-js@1.11.22 dropping a postinstall remote payload. Microsoft attributes the campaign to Sapphire Sleet (North Korea–nexus, lineage to the Axios/APT38 npm activity); Nextron flagged related infostealer packages whose Rust second stage hunts crypto seed phrases, .env/.npmrc/SSH keys, and enumerates SentinelOne, Defender, and Little Snitch on macOS. The Hacker News, Microsoft · Cloud, Identity & Supply Chain

in FortiBleed Burns 86,000 FortiGate Devices as Novo Nordisk Loses 1.3TB — Including AI Models — to a Leaked GitHub Token