logo

144 Mastra npm Packages Compromised via Hijacked Contributor Account

ID: b4ac28b4-c6f8-52db-bbe1-7328a39c35e5

STIX ID: report--b4ac28b4-c6f8-52db-bbe1-7328a39c35e5

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: [email protected] (The Hacker News)

...
...

## Executive Summary As many as 144 @mastra npm packages were compromised in a supply-chain campaign (easy-day-js) that injected a malicious dependency which executes an obfuscated postinstall loader to download a second-stage cross-platform information stealer; the malware harvests browser history, data from over 160 cryptocurrency wallet extensions, installs persistence on Windows/macOS/Linux, and exfiltrates data to attacker C2 servers (23.254.164.92 and 23.254.164.123).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.