Cybersecurity firm CrowdStrike stated on August 3 that a North Korea-linked attacker injected malicious dependencies into at least 131 Mastra AI framework packages on npm (Node Package Manager). Microsoft-owned GitHub acquired npm in 2020 and operates the core registry in this attack chain. The attacker published tampered Mastra versions containing the malicious dependency "easy-day-js" using stolen maintainer credentials. This dependency runs during installation, exposing developers' machines and build pipelines to credential theft and remote code execution risks. CrowdStrike found that 87% of software registry threats identified in the first half of 2026 involved npm packages.