North Korean Hackers Used a Fake LinkedIn Job Offer to Poison an AI Framework North Korea's STARDUST CHOLLIMA hacking group social-engineered a maintainer of the Mastra AI framework with a fake LinkedIn job pitch, then used stolen credentials to poison 131 npm packages, according to CrowdStrike's 2026 Threat Hunting Report released August 3. The same group compromised the Axios HTTP client library in March 2026, delivering ZshBucket malware. CrowdStrike found that AI-enabled adversary activity climbed 89% year-over-year, with 87% of software registry threats involving malicious npm packages. North Korea's STARDUST CHOLLIMA hacking group social-engineered a maintainer of the Mastra AI framework with a fake LinkedIn job pitch, then used the stolen access to poison 131 npm packages that AI developers install by the thousands. Here's how it went down. According to CrowdStrike's 2026 Threat Hunting Report, released August 3, the group approached a Mastra maintainer on LinkedIn with a phony job pitch, moved the conversation to a video call, and talked them into clicking a malicious link. That single click was enough. In June 2026, using the credentials it harvested, STARDUST CHOLLIMA injected malicious npm code as a dependency into at least 131 Mastra packages, according to CrowdStrike. A Pattern, Not a One-Off Mastra isn't some obscure side project. It's one of the more widely adopted open-source frameworks startups use to build AI agents, the kind of tooling that gets pulled into a codebase with a single npm install and barely a second thought. That's exactly why it was a target. You don't need to breach a company's firewall anymore. You just need to convince one person with commit access to click the wrong thing on a video call. In March 2026, the same group used stolen maintainer credentials to compromise Axios, the HTTP client library that gets downloaded more than 100,000 times a week. That breach delivered ZshBucket, malware CrowdStrike has tied to STARDUST CHOLLIMA with moderate confidence. The Axios variants were notable for a reason beyond the headline count: they ran across Linux, macOS, and Windows through a shared JSON-based messaging protocol, letting the group manage every infected machine through one channel instead of juggling separate tools per operating system. Google's Threat Intelligence Group has attributed the same campaign to a related North Korean cluster it tracks as UNC1069. Two compromises, one group, three months apart. That's not a fluke. It's a pattern, and CrowdStrike's data backs it up: 87% of software registry threats the firm identified in the first half of 2026 involved malicious npm packages. JavaScript's dependency chains and automatic install scripts make it the easiest ecosystem to poison and the hardest to fully audit, and adversaries have clearly noticed. Zoom out further and the trend gets uglier. CrowdStrike found that AI-enabled adversary activity overall climbed 89% year-over-year, with groups using AI to speed up reconnaissance, credential theft, and evasion. One campaign the firm tracked sent nearly 200,000 requests to an AI model in two minutes flat. That's not a typo. Attackers are moving faster than defenders can watch, and they're doing it with tools that used to be exclusively on the defense side of the ledger. What It Means for AI Startups Frankly, the Mastra breach should worry anyone building on open-source AI tooling more than the Axios one did. Axios is infrastructure plumbing. Mastra is the scaffolding startups are racing to build actual products on top of, often with small teams who don't have the security review process a bank or a defense contractor would run before adding a dependency. When a nation-state group can get inside that scaffolding with a fake job offer and a Zoom call, the entry cost for compromising an AI startup's entire stack just got a lot cheaper. None of this required a zero-day. It required patience, a convincing LinkedIn profile, and one maintainer who believed the call was real. That's it. That's the whole attack. That's the uncomfortable part for founders who assume their security posture is about firewalls and access controls. The weak point was a person, not a server. STARDUST CHOLLIMA knew exactly which person to target. CrowdStrike hasn't said whether Mastra's maintainers have since revoked the compromised credentials or audited every downstream package that pulled in the poisoned dependency. What's clear is that recruiter DMs on LinkedIn are now a genuine attack surface for the people writing the code your AI agents run on. Treating them that way isn't paranoia anymore. It's basic hygiene. Also read: AMD posts record $11.5 billion quarter but the stock still falls almost 9% https://startupfortune.com/amd-posts-record-115-billion-quarter-but-the-stock-still-falls-almost-9/ • Intel Stock Jumps 10% as Trump's Government Stake Gains Keep Climbing https://startupfortune.com/intel-stock-jumps-10-as-trumps-government-stake-gains-keep-climbing/ • Samsung Unveils zHBM Memory That Runs Eight Times Faster Than HBM5 https://startupfortune.com/samsung-unveils-zhbm-memory-that-runs-eight-times-faster-than-hbm5/