Hackers Target npm Ecosystem by Compromising 140+ Mastra Packages
ID: 36bdd8bd-40db-5c77-931b-1abaa53fe47b
STIX ID: report--36bdd8bd-40db-5c77-931b-1abaa53fe47b
Feed Name: GBHackers
A supply-chain campaign disclosed on June 17, 2026 compromised 141 Mastra npm packages by injecting a typosquatted dependency (easy-day-js) that executed a postinstall loader to fetch a second-stage Node.js implant (protocal.cjs); the malware establishes cross-platform persistence, performs host reconnaissance and crypto-wallet extension enumeration, and communicates with attacker-controlled C2 infrastructure. The report provides IOCs (C2 IPs/URLs, file names, persistence artifacts, SHA256 hashes) and recommends removing malicious package versions, rebuilding clean dependencies, eradicating persistence, rotating credentials, and enforcing stricter dependency controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
