CrowdStrike Holdings, Inc. (NASDAQ:CRWD) said on August 3 that a North Korea-linked adversary injected a malicious dependency into at least 131 Mastra AI framework packages on npm (Node Package Manager). Microsoft Corporation (NASDAQ:MSFT) owns GitHub, which acquired npm in 2020 and operates the registry at the center of the attack chain.
This was a developer-supply-chain breach with unusually efficient distribution. Stolen maintainer credentials let the attacker publish poisoned Mastra versions tagged as the latest releases. The malicious easy-day-js dependency then ran during installation, exposing developer machines and build pipelines to credential theft and remote code execution. CrowdStrike found that 87% of identified software-registry threats in the first half of 2026 involved npm packages.

Image by Tawanda Razika from Pixabay
Microsoft’s role cuts both ways. GitHub controls the registry infrastructure, and its advisory database powers npm audit, so repeated account takeovers increase the burden to harden publishing and dependency scanning. Yet Microsoft’s own June 17 investigation identified more than 140 affected Mastra packages and detailed detections across Defender Antivirus, Defender for Endpoint and Defender XDR. The same incident that creates reputational risk for npm also gives Microsoft another reason to sell integrated security.
The more direct demand read-through belongs to CrowdStrike. Its fiscal Q1 2027 revenue grew 26% to $1.39 billion, while annual recurring revenue rose 24% to $5.51 billion. Hedge-fund ownership also increased to 79 portfolios at the end of Q1 2026 from 67 in Q4 2025, according to Insider Monkey’s database. The valuation is the restraint: a roughly $190 billion market value equals about 32 times CrowdStrike’s $5.91 billion to $5.96 billion fiscal-year revenue guidance. The business must sustain growth near the mid-20% range for that multiple to remain comfortable.
At that valuation, the attack changes the stock case only if CrowdStrike converts the demand signal into new modules, larger contracts, and durable recurring revenue.
July 15 short interest stood at 27.45 million shares, 2.79% of float, with roughly 2.3 days to cover on Finviz’s current volume calculation. The nominal share count followed CrowdStrike’s July 2 four-for-one split, so it should not be mistaken for a sudden fourfold bearish move.
Microsoft Corporation (NASDAQ:MSFT) generated $90.0 billion of quarterly revenue on July 29, up 18%, with Azure growing 43%. That scale makes one npm compromise financially immaterial. CrowdStrike Holdings, Inc. (NASDAQ:CRWD) gets the stronger demand signal, but its valuation makes the stock a hold rather than a chase. Microsoft remains the better core holding because it owns both the vulnerable developer channel and a security stack that can monetize the repair.
While we acknowledge the risk and potential of MSFT and CRWD as investments, our conviction lies in the belief that some AI stocks hold greater promise for delivering higher returns and doing so within a shorter time frame. If you are looking for an AI stock that is more promising than MSFT and CRWD and that has 10,000% upside potential, check out our report about this cheapest AI stock.
READ NEXT: 33 Stocks That Should Double in 3 Years and 15 Stocks That Will Make You Rich in 10 Years
Disclosure: None. Follow Insider Monkey on Google News.






