EPISODE · Jul 24, 2026 · 10 MIN
North Korea Mastra NPM Supply Chain Attack: How It Works
from Plaintext with Rich · host Rich Greene
You installed a dependency before lunch. Tests passed, app booted, nothing looked wrong. By dinner, your machine had quietly run someone else's code.This episode covers the Mastra npm supply chain compromise Microsoft attributed to North Korea linked threat actors. We break down how postinstall scripts became the attack vector, why an 88 minute exposure window still matters, and what remote access trojans do on developer endpoints. You will learn how AI framework supply chains expand your attack surface, the difference between package takedown and forensic cleanup, and why lockfiles are history snapshots not security verdicts. We walk through the controls that protect teams most: deterministic builds with pinned versions and provenance attestations for verified package origins. The episode includes timeline thinking for exposure windows, hunting for execution artifacts beyond package names, and the specific steps for rotating secrets and rebuilding compromised environments.This is for developers, security teams, and engineering leaders managing open source dependencies in fast moving stacks.One Topic, Ten minutes, No panic.Is there a topic/term you want me to discuss next? Text me!!YouTube more your speed? → https://links.sith2.com/YouTube Apple Podcasts your usual stop? → https://links.sith2.com/Apple Neither of those? Spotify’s over here → https://links.sith2.com/Spotify Prefer reading quietly at your own pace? → https://links.sith2.com/Blog Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord Follow the human behind the microphone → https://links.sith2.com/linkedin Need another way to reach me? That’s here → https://linktr.ee/rich.greene
Embed this episode
What this episode covers
You installed a dependency before lunch. Tests passed, app booted, nothing looked wrong. By dinner, your machine had quietly run someone else's code. This episode covers the Mastra npm supply chain compromise Microsoft attributed to North Korea linked threat actors. We break down how postinstall scripts became the attack vector, why an 88 minute exposure window still matters, and what remote access trojans do on developer endpoints. You will learn how AI framework supply chains expand your ...
NOW PLAYING
North Korea Mastra NPM Supply Chain Attack: How It Works
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.