North Korean state-sponsored group Sapphire Sleet (BlueNoroff) compromised an npm maintainer account with publishing rights across the Mastra AI agent framework’s package scope and, within a roughly 45-minute window, pushed malicious updates to more than 140 packages with a combined 8 million weekly downloads. The updates injected a typosquatted dependency that deployed infostealer malware targeting 166 cryptocurrency wallet browser extensions across Windows, Linux, and macOS. Microsoft attributed the campaign to Sapphire Sleet with high confidence, noting the group primarily targets the financial sector.