World Model · podcast knowledge graph

North Korea Mastra NPM Supply Chain Attack: How It Works

2026-07-24 · 10 min · episode 35 · 6 entities

Asserted relationships

  • → hosted by Rich Greene person
    0.55
    evidence rules-v5
    Feed author/publisher: Rich Greene
  • → discusses Technology company
    0.40
    evidence rules-v5
    Feed category: Technology

Entities found in this episode

persons 2

  • mentioned Rich Greene person
    0.70
    evidence rules-v5
    Feed author/publisher: Rich Greene
  • hosted by Rich Greene person
    0.55
    evidence rules-v5
    Feed author/publisher: Rich Greene

companys 2

  • mentioned Technology company
    0.50
    evidence rules-v5
    Feed category: Technology
  • discusses Technology company
    0.40
    evidence rules-v5
    Feed category: Technology

concepts 2

  • mentioned How It Works concept
    0.42
    evidence rules-v5
    North Korea Mastra NPM Supply Chain Attack: How It Works
  • mentioned NPM concept
    0.35
    evidence rules-v5
    NPM
Episode description as stored
You installed a dependency before lunch. Tests passed, app booted, nothing looked wrong. By dinner, your machine had quietly run someone else's code. This episode covers the Mastra npm supply chain compromise Microsoft attributed to North Korea linked threat actors. We break down how postinstall scripts became the attack vector, why an 88 minute exposure window still matters, and what remote access trojans do on developer endpoints. You will learn how AI framework supply chains expand your attack surface, the difference between package takedown and forensic cleanup, and why lockfiles are history snapshots not security verdicts. We walk through the controls that protect teams most: deterministic builds with pinned versions and provenance attestations for verified package origins. The episode includes timeline thinking for exposure windows, hunting for execution artifacts beyond package names, and the specific steps for rotating secrets and rebuilding compromised environments. This is for developers, security teams, and engineering leaders managing open source dependencies in fast moving stacks. One Topic, Ten minutes, No panic. Is there a topic/term you want me to discuss next? Text me!! YouTube more your speed? → https://links.sith2.com/YouTube   Apple Podcasts your usual stop? → https://links.sith2.com/Apple   Neither of those? Spotify’s over here → https://links.sith2.com/Spotify   Prefer reading quietly at your own pace? → https://links.sith2.com/Blog   Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord   Follow the human behind the microphone → https://links.sith2.com/linkedin   Need another way to reach me? That’s here → https://linktr.ee/rich.greene