Crowdstrike Holdings IncCrowdStrike's report highlights demand for integrated security solutions, benefiting its products.
CrowdStrike reported that a North Korea-linked adversary injected a malicious dependency into at least 131 Mastra AI framework packages on npm, the Node Package Manager owned by Microsoft's GitHub. Stolen maintainer credentials allowed the attacker to publish poisoned versions tagged as latest, with the malicious easy-day-js dependency running during installation to expose developer machines and build pipelines to credential theft and remote code execution. CrowdStrike noted that 87% of identified software-registry threats in the first half of 2026 involved npm packages. Microsoft's own investigation identified more than 140 affected Mastra packages and detailed detections across its Defender security products. The incident highlights demand for integrated security solutions, benefiting CrowdStrike, which reported fiscal Q1 2027 revenue of $1.39 billion and annual recurring revenue of $5.51 billion, though its roughly $190 billion market value trades at about 32 times fiscal-year revenue guidance.
Crowdstrike Holdings IncCrowdStrike's report highlights demand for integrated security solutions, benefiting its products.
Microsoft CorporationMicrosoft's npm platform was used to distribute malicious packages, raising security concerns and potential regulatory scrutiny.