logo

Hackers Compromise 140+ Mastra npm Packages to Steal Credentials

ID: 7e9cd157-9831-56ae-a6db-0ac180765571

STIX ID: report--7e9cd157-9831-56ae-a6db-0ac180765571

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Lucas Martin

...
...

An active npm supply-chain attack compromised 141 @mastra/* packages by adding a malicious transitive dependency (easy-day-js) that executes a postinstall downloader. The second-stage Node.js implant establishes cross-platform persistence, harvests 166 cryptocurrency wallet extensions, browser history, and developer credentials, and exfiltrates data to attacker-controlled IPs; Microsoft and Socket independently confirmed the campaign and the report provides IOCs and mitigation steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.