A sophisticated supply chain campaign, attributed to the suspected threat actor TeamPCP, has simultaneously targeted the Mastra AI framework via npm, GitHub Actions CI/CD workflows, and the Arch Linux User Repository (AUR). The attack utilized dormant contributor account takeovers to poison the @mastra npm scope using the easy-day-js dependency and hijacked GitHub Action version tags to exfiltrate CI/CD credentials. Additionally, over 1,500 AUR packages were compromised with eBPF-based rootkit malware. This coordinated infrastructure, linked by the "Mini Shai-Hulud" worm, facilitates widespread code execution, credential theft, and persistent rootkit deployment across development, DevOps, and end-user Linux environments.
-
Incident Overview and Scope
- Targeted Ecosystems: Simultaneous strikes against the npm registry (@mastra scope), GitHub Actions (DevOps pipelines), and the Arch Linux User Repository (AUR).
- Scale of Impact: Compromise of 144 Mastra AI packages, redirection of widely-used GitHub Actions, and infection of approximately 1,500 AUR packages.
- Coordinated Infrastructure: The campaign is unified by the "Mini Shai-Hulud" worm, linking disparate attack vectors into a single, multi-stage operation.
-
Attack Vector Mechanics
- npm Dependency Poisoning: Attackers utilized dormant contributor account takeovers to inject malicious code into the
@mastrascope, specifically leveraging theeasy-day-jsdependency for resolution hijacking. - CI/CD Tag Hijacking: Exploited
actions-coolworkflows by redirecting version tags, allowing the interception and exfiltration of sensitive GitHub Actions secrets. - Linux Kernel Exploitation: Deployed eBPF-based rootkit-like malware within the AUR to achieve stealthy, high-privilege persistence on Linux-based user environments.
- npm Dependency Poisoning: Attackers utilized dormant contributor account takeovers to inject malicious code into the
-
Malware and Payload Profile
- Shai-Hulud/Mini Shai-Hulud: A sophisticated worm/infrastructure used to bridge the gap between npm dependency poisoning and CI/CD hijacking.
- Payload Functionality: Payloads include cross-platform cryptocurrency stealers and deep-system rootkits designed for long-term environmental persistence.
- Evasion Techniques: Utilization of eBPF allows for kernel-level stealth, making detection via traditional user-space security tooling difficult.
-
Threat Actor Profile and Systemic Risk
- Attribution: The complexity and coordination of the campaign strongly suggest the involvement of the TeamPCP threat group.
- Lifecycle Compromise: The attack demonstrates an ability to compromise the entire software development lifecycle (SDLC), from AI framework development to production deployment.
- Strategic Impact: The targeting of AI ecosystems (Mastra) and DevOps tooling (GitHub Actions) indicates a high-intent focus on modern enterprise infrastructure.
-
Defensive Recommendations
- Supply Chain Integrity: Implement strict dependency pinning and integrity verification (e.g., SHA-256 hashes) rather than relying on floating version tags or semantic versioning.
- CI/CD Hardening: Use immutable commit SHAs for all GitHub Actions to prevent version tag hijacking and secret exfiltration.
- Linux Security Monitoring: Deploy eBPF-aware security monitoring to detect unauthorized kernel-level programming and anomalous system calls.
Related posts
- feeds.feedburner.com — GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension
- Armorcode
- Safestate
- Bankinfosecurity
- Security Affairs — Supply Chain Attack Hits Popular WordPress Plugins Through Awesome Motive CDN
- feeds.feedburner.com — Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites
- cyberinsider.com — Supply-chain attack hits OptinMonster plugin used in 1.2 million WordPress sites
- Infosecurity-magazine
- techjacksolutions.com — CDN Key Theft Turns Three WordPress Plugins Into Backdoor Delivery Networks Across 1.2 Million Sites
- arXiv (Computer Science - Cryptography and Security) — Cordyceps: Covert Control Attacks on LLMs via Data Poisoning
- Cybersecurity News — OptinMonster Plugin Hack Exposes 1.2 Million WordPress Sites to Cyberattack
- gbhackers.com — OptinMonster Plugin Vulnerability Exposes 1.2 Million WordPress Sites to Cyberattacks
- threat-modeling.com — OptinMonster WordPress Plugin CDN Supply-Chain Attack: 1.4 Million Sites Affected
- appsec.fyi — Mastra AI Framework Poisoned in npm Supply-Chain Attack
- Microsoft Security Blog — From package to postinstall payload: Inside the Mastra npm supply chain compromise
- appsec.fyi — A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope
- penligent.ai — Mastra npm Supply Chain Attack, What easy-day-js Did and How to Respond
- DEV Community — Beyond SLSA: How to Stop Zero-Click CI/CD Worms with a 9-Step Plan
- Hexnode Blog — Mastra npm Supply-Chain Attack Compromises 144 AI Framework Packages
- appsec.fyi — Supply-chain malware is evolving into self-propagating worms
- techjacksolutions.com — Tag Hijacking in actions-cool Workflows Exposes CI/CD Pipelines to Active Credential Exfiltration
- threatlocker.com — The Mastra supply chain attack wasn't about AI
- Labs
- Privacyguides
- Exchange
- Resconinc
- Stepsecurity
- bleepingcomputer.com — Microsoft links Mastra AI supply chain attack to North Korean hackers
- techjacksolutions.com — Sapphire Sleet Escalates npm Campaign: 140+ Mastra AI Packages Weaponized to Harvest Credentials and Crypto Wallets
- Daily
- threat-modeling.com — North Korean Hackers Linked to Mastra AI Supply Chain Attack — AI/ML Ecosystem Targeted
- gbhackers.com — Sapphire Sleet Hijacks npm Maintainer Account to Publish Poisoned Mastra Packages
- gbhackers.com — GitHub Actions Checkout Adds Protection Against Malicious pull_request_target Workflows
- Cybersecurity News — Hackers Compromised 10,000+ GitHub Repositories to Inject Malicious Script
- Cybersecurity News — North Korean Hackers Abuse Mastra npm Supply Chain to Target Developers and CI/CD Pipelines
- techjacksolutions.com — Weekly Security Intelligence Briefing — Week of 2026-06-22
- Callmissed
- Kodaapi
- Iipoman
- Medium
- Axipro
- Securityweek
- Foresiet
- News4Hackers — GitHub Supply Chain Attack: 10,000 Malicious Clones Spread Trojan ZIPs
- Aiweekly
- Bankinfosecurity
- Thehackernews
- Orca
- Tenable Blog — What the Miasma campaign reveals about the new supply chain threat model and the underground market for developer credentials
- Securityweek
- falconinternet.net — Cordyceps: The CI/CD Flaw That Could Poison the Code You Trust
- datawater.com — Cordyceps: A Free GitHub Account Is All It Takes to Hijack CI/CD Pipelines at Microsoft, Google, Apache, and Cloudflare — 300+ Repos Confirmed Exploitable
- techjacksolutions.com — Ecosystem: Node.js / npm / PyPI / VSCode Extension Ecosystem (Glassworm Campaign) — Vulnerability Rollup (2026-05-26)
- thecyberexpress.com — Iranian Hacker Arrested Over Alleged $3.4 Billion Cyberattack on USA Infrastructure
- Malware News — Operation DragonReturn: China-Nexus Cyber Espionage Campaign Targeting Govt. of India/MoF Tax Infrastructure via Multi-Stage DcRAT Deployment
- gbhackers.com — China-Linked Malware Found in Counterfeit USB Drives Used on Japan Defense Force Classified Networks
- gbhackers.com — Massive GitHub Attack Injects Malware into 10,000 Compromised Repositories
- Cybersecurity News — GitHub Actions Checkout Update Blocks Workflows Triggered by Malicious pull_request_target
- Crowdstrike
- csoonline.com — GlassWorm falls, but the repo problem is far from solved
- appsec.fyi — AUR suspends new registrations as 1500-plus malicious packages flood repository
- Feedly
- Thehackernews
- Blog
- Datadoghq
- Redcanary
- Reversinglabs
- Antiy
- Labs
- Securityboulevard
- Aiweekly
- Hackread
- Novee
- Rootdata
- Microsoft Security Blog — Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access
- Binance
- App
- Securityaffairs
- Thehackernews
- Darkreading
- Checkmarx
- Thehackernews
- Techradar
- Socprime
- Balkanweb
- Democrata
- Kashmirlife
- Inss
- Promisedu
- Dmarcreport
- Strategicmarketresearch
- Mdpi
- Researchgate
- Securereading
- Securitymagazine
- Eastmidlandscybersecure
- Securityscorecard
- Community
- Safedep
- Stepsecurity
- Neuracybintel
- SecurityWeek — Atomic Arch Supply Chain Attack Hits 1,500 AUR Packages
- Dark Reading — 'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows