Synk (likely Snyk), a developer security company, analyzed the Mastra campaign and noted strong similarities to the Axios npm compromise, including clean-then-armed dependencies, postinstall droppers, TLS bypass, and crypto-stealer payloads that self-delete.