logo

RST TI Report Digest: 22 Jun 2026

ID: 4e7bec94-8be3-5612-82d6-1405f9634685

STIX ID: report--4e7bec94-8be3-5612-82d6-1405f9634685

Feed Name: RST Cloud Blog

Threat Score
88/100

Date Published: 2026-06-22

Date Updated: 2026-06-22

Author: RST Cloud

...
...

Mastra is a high-impact npm supply-chain compromise in which an attacker took over a dormant maintainer and published >140 malicious packages (typo-squatted 'easy-day-js') that used postinstall hooks to install a two-stage downloader and cross-platform backdoor. The payload enables host fingerprinting, persistence, remote code execution, and theft of browser history, credentials, password managers, authenticators, and crypto wallet-extension data across Windows, macOS, and Linux; the report provides multiple IOCs (IPs, domains, package hashes, emails, and many browser extension IDs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.