Feed144 Mastra npm Packages Compromised via Hijacked Contributor...
The Hacker News

144 Mastra npm Packages Compromised via Hijacked Contributor Account

📅 17 June 2026 at 07:38 UTC📰 The Hacker NewsView original source ↗
144 Mastra npm Packages Compromised via Hijacked Contributor Account

As many as 144 npm packages associated with the Mastra namespace ("@mastra/*"), a popular open-source JavaScript and TypeScript framework for building artificial intelligence (AI) applications, have been compromised as part of a software supply chain attack codenamed easy-day-js, per findings from JFrog, SafeDep, Socket, and StepSecurity. "A single npm account (ehindero) mass-published more

Read the full article

This is a curated summary. The complete article is available at The Hacker News.

Read on The Hacker News
← Back to feed