RST TI Report Digest: 22 Jun 2026
ID: 4e7bec94-8be3-5612-82d6-1405f9634685
STIX ID: report--4e7bec94-8be3-5612-82d6-1405f9634685
Feed Name: RST Cloud Blog
Mastra is a high-impact npm supply-chain compromise in which an attacker took over a dormant maintainer and published >140 malicious packages (typo-squatted 'easy-day-js') that used postinstall hooks to install a two-stage downloader and cross-platform backdoor. The payload enables host fingerprinting, persistence, remote code execution, and theft of browser history, credentials, password managers, authenticators, and crypto wallet-extension data across Windows, macOS, and Linux; the report provides multiple IOCs (IPs, domains, package hashes, emails, and many browser extension IDs).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
