logo

Hackers Target npm Ecosystem by Compromising 140+ Mastra Packages

ID: 36bdd8bd-40db-5c77-931b-1abaa53fe47b

STIX ID: report--36bdd8bd-40db-5c77-931b-1abaa53fe47b

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Divya

...
...

A supply-chain campaign disclosed on June 17, 2026 compromised 141 Mastra npm packages by injecting a typosquatted dependency (easy-day-js) that executed a postinstall loader to fetch a second-stage Node.js implant (protocal.cjs); the malware establishes cross-platform persistence, performs host reconnaissance and crypto-wallet extension enumeration, and communicates with attacker-controlled C2 infrastructure. The report provides IOCs (C2 IPs/URLs, file names, persistence artifacts, SHA256 hashes) and recommends removing malicious package versions, rebuilding clean dependencies, eradicating persistence, rotating credentials, and enforcing stricter dependency controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.