URL has been copied successfully!
145 Mastra npm Packages Compromised via Hijacked Contributor Account
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

145 Mastra npm Packages Compromised via Hijacked Contributor Account

As many as 145 npm packages associated with the Mastra namespace (“@mastra/*”), a popular open-source JavaScript and TypeScript framework for building artificial intelligence (AI) applications, have been compromised as part of a software supply chain attack codenamed easy-day-js, per findings from Endor Labs, JFrog, OX Security, SafeDep, Socket, StepSecurity, and Synk.”A single npm account (

First seen on thehackernews.com

Jump to article: thehackernews.com/2026/06/144-mastra-npm-packages-compromised-via.html

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link