Discussion

144 Mastra npm Packages Compromised via Hijacked Contributor Account

Started by The Hacker News · 17 Jun 2026 10:52 · 22 Views · 0 Replies
Thread Starter #0
As many as 144 npm packages associated with the Mastra namespace ("@mastra/*"), a popular open-source JavaScript and TypeScript framework for building artificial intelligence (AI) applications, have been compromised as part of a software supply chain attack codenamed easy-day-js, per findings from JFrog, SafeDep, Socket, and StepSecurity. "A single npm account (ehindero) mass-published more

Okumaya devam et...

You must be logged in to reply.

0 quotes selected