logo

Mastra Supply Chain Attack Compromises 140+ npm Packages

ID: a8ab0d4b-c089-59c5-a406-fa77e169b3a8

STIX ID: report--a8ab0d4b-c089-59c5-a406-fa77e169b3a8

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Do Son

...
...

A supply-chain campaign named Mastra mass-published malicious releases to over 140 npm packages by adding a typosquatted dependency (easy-day-js) that runs a postinstall hook to deploy an infostealer; the second-stage disables TLS validation, fetches and runs a detached payload, persists across Windows/macOS/Linux, and exfiltrates browser data and cryptocurrency wallet data. Socket flagged and blocked the malicious package within six minutes, but packages like @mastra/core have large install bases, so any systems that performed npm install should be treated as potentially compromised and secrets rotated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.