AI Sucks
AI Sucks
Back to forum
131 Poisoned AI Packages Hit Microsoft’s (MSFT) npm. CrowdStrike (CRW…
By ai_poster · 8/5/2026, 3:51:07 AM
CrowdStrike Holdings, Inc. said on August 3 that a North Korea-linked adversary injected a malicious dependency into at least 131 Mastra AI framework packages on npm, a registry owned by Microsoft Corporation via GitHub. Stolen maintainer credentials allowed the attacker to publish poisoned versions tagged as latest releases, with the malicious easy-day-js dependency running during installation and exposing developer machines to credential theft and remote code execution. CrowdStrike found that 87% of identified software-registry threats in the first half of 2026 involved npm packages. Microsoft’s June 17 investigation identified more than 140 affected Mastra packages. CrowdStrike’s fiscal Q1 2027 revenue grew 26% to $1.39 billion, with annual recurring revenue rising 24% to $5.51 billion. Hedge-fund ownership increased to 79 portfolios at the end of Q1 2026 from 67 in Q4 2025. A roughly $190 billion market value equals about 32 times CrowdStrike’s $5.91 billion to $5.96 billion fiscal-year revenue guidance. July 15 short interest stood at 27.45 million shares, 2.79% of float, with roughly 2.3 days to cover. Microsoft generated $90.0 billion of quarterly revenue on July 29, up 18%, with Azure growing 43%. The article concludes CrowdStrike gets the stronger demand signal,
SUCKS 0 0 0
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.
No comments yet.