logo

The Mastra supply chain attack wasn't about AI

ID: 95f26bbc-1894-52e2-bd8f-9826fd8dea88

STIX ID: report--95f26bbc-1894-52e2-bd8f-9826fd8dea88

Feed Name: ThreatLocker Blog

Threat Score
85/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

...
...

In June 2026, a maintainer account compromise in the @mastra npm scope led to over 140 packages being republished with a malicious dependency ('easy-day-js') that used npm lifecycle hooks to execute, spawn a detached second-stage payload, and perform credential theft and malware delivery; the report emphasizes this as a conventional supply-chain attack affecting AI frameworks and recommends controls such as allowlisting and ringfencing to limit what trusted runtimes may do.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.