Cryptocurrency-Stealing Remote Access Trojan Deployed in Mastra Attack
A cross-platform information stealer deployed as the final payload in the Mastra supply chain attack. It harvests browser history, steals data from…
A cross-platform information stealer deployed as the final payload in the Mastra supply chain attack. It harvests browser history, steals data from…
Synk (likely Snyk), a developer security company, analyzed the Mastra campaign and noted strong similarities to the Axios npm compromise, including clean-then-armed…
Mastra is an open-source JavaScript and TypeScript framework for building AI applications. In June 2026, 145 of its npm packages were compromised…
@mastra/core is the core npm package of the Mastra AI framework, receiving over 918K weekly downloads. It was among the 145 packages…
On June 17, 2026, a software supply chain attack codenamed 'easy-day-js' compromised 145 npm packages under the @mastra/* namespace, a popular open-source…