CyberSecurityBoardThreat Intel · CVEs · Products
Cyber Companies

Mastra: Open-Source AI Framework Hit by Supply Chain Attack

June 25, 2026

Mastra is an open-source JavaScript and TypeScript framework for building AI applications. In June 2026, 145 of its npm packages were compromised after a maintainer's account was hijacked via social engineering. The company responded by unpublishing malicious versions, removing token bypass, and requiring MFA. They confirmed the root cause was a compromised employee machine.