Over 140 popular Mastra npm Packages Hit by Supply Chain Attack
ID: 6550a099-ecd6-5a63-92d2-19d817980e3e
STIX ID: report--6550a099-ecd6-5a63-92d2-19d817980e3e
Feed Name: Aikido Security's Blog
Threat Score
On June 17 a supply-chain attack republished 141 packages in the @mastra npm scope, adding a malicious dependency ([email protected]) that leverages a postinstall hook to download and execute a second-stage RAT; the dropper contacts C2 infrastructure (23.254.164.92:8000 / 23.254.164.123:443), targets over 160 browser crypto wallet extensions (e.g., MetaMask, Keplr, Coinbase), establishes cross-platform persistence, and self-deletes to evade forensics.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
