Supply Chain Threats Hit Mastra AI and Open‑Source Packages
A sophisticated multi‑vector supply‑chain campaign attributed to the TeamPCP threat group targeted the Mastra AI framework. Attackers poisoned the @mastra scope on npm, hijacked GitHub Actions tags to steal CI/CD credentials, and compromised roughly 1,500 Arch Linux User Repository (AUR) packages with eBPF‑based rootkits. The operation, linked by the "Mini Shai‑Hulud" worm, affected 144 Mastra AI packages and leveraged dormant contributor account takeovers to inject malicious code.
In a separate wave, researchers identified the PolinRider campaign, tied to North Korean actors. The campaign hides malicious JavaScript loaders inside legitimate‑looking open‑source packages across npm, Packagist, Go modules and even a Chrome extension. Over 162 malicious releases were found in 108 unique packages, including 80 compromised Go modules. Loaders are concealed in config files or fake font files and are triggered via Visual Studio Code tasks. Once active, they fetch encrypted second‑stage payloads such as DEV#POPPER and OmniStealer, stealing credentials, browser data and cryptocurrency wallet information. The campaign also involved forced pushes and back‑dated commits on GitHub accounts like Xpos587 to rewrite history and evade detection.