logo

144 Mastra npm Packages Compromised via Hijacked Contributor Account

ID: 372b7c67-ab5c-5661-b2ca-fb45ebfa678c

STIX ID: report--372b7c67-ab5c-5661-b2ca-fb45ebfa678c

Feed Name: CosmicBytez Labs

Threat Score
88/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

...
...

A supply-chain campaign dubbed "easy-day-js" hijacked a contributor account to publish malicious, trojanized versions of 144 packages in the @mastra/* npm namespace; the packages likely executed payloads via npm lifecycle scripts and could exfiltrate developer and CI/CD secrets. The report details the attack chain, potential impact on developer workstations, CI/CD pipelines, and downstream projects, and provides immediate remediation steps (audit lockfiles, rotate secrets, pin versions, enable npm audit) and longer-term hardening recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.