144 Mastra npm Packages Compromised via Hijacked Contributor Account
ID: 372b7c67-ab5c-5661-b2ca-fb45ebfa678c
STIX ID: report--372b7c67-ab5c-5661-b2ca-fb45ebfa678c
Feed Name: CosmicBytez Labs
A supply-chain campaign dubbed "easy-day-js" hijacked a contributor account to publish malicious, trojanized versions of 144 packages in the @mastra/* npm namespace; the packages likely executed payloads via npm lifecycle scripts and could exfiltrate developer and CI/CD secrets. The report details the attack chain, potential impact on developer workstations, CI/CD pipelines, and downstream projects, and provides immediate remediation steps (audit lockfiles, rotate secrets, pin versions, enable npm audit) and longer-term hardening recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
