FeedHackers Compromised 140+ Mastra npm Packages to Deploy Passw...
Cyber Security News

Hackers Compromised 140+ Mastra npm Packages to Deploy Password-Stealing Malware

📅 17 June 2026 at 09:05 UTC📰 Cyber Security NewsView original source ↗
Hackers Compromised 140+ Mastra npm Packages to Deploy Password-Stealing Malware

A sophisticated supply chain attack has targeted the Mastra-AI npm ecosystem, with researchers from Microsoft and Socket identifying over 141 compromised packages designed to silently deploy an infostealer payload on developer machines, CI/CD runners, and build environments. The campaign, detected on June 17, 2026, exploited a typosquatting dependency to deliver multi-stage malware capable of stealing […] The post Hackers Compromised 140+ Mastra npm Packages to Deploy Password-Stealing Malware appeared first on Cyber Security News.

Read the full article

This is a curated summary. The complete article is available at Cyber Security News.

Read on Cyber Security News
← Back to feed