CyberSecurityBoardThreat Intel · CVEs · Products
Malware

Cryptocurrency-Stealing Remote Access Trojan Deployed in Mastra Attack

June 25, 2026

A cross-platform information stealer deployed as the final payload in the Mastra supply chain attack. It harvests browser history, steals data from over 160 cryptocurrency wallet browser extensions, installs persistence on Windows, macOS, and Linux, and exfiltrates data to a C2 server. It also polls the C2 for commands to download and execute additional modules.