logo

Mastra supply chain attack: The importance of scope access and account hygiene

ID: fa807da2-ae89-501a-a5a3-5f16517b47a5

STIX ID: report--fa807da2-ae89-501a-a5a3-5f16517b47a5

Feed Name: ThreatLocker Blog

Threat Score
88/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

...
...

A supply-chain attack against the @mastra npm scope used a typosquatted package ('easy-day-js') and a compromised maintainer account to republish over 140 packages, deploying a two-stage Node.js infostealer that performs OS-specific data collection (browser data, password managers, crypto wallets), establishes persistence on Windows/macOS/Linux, and communicates with hardcoded C2 hosts and DGA domains; the report includes network and file IOCs, SHA-256 hashes, and remediation/mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.