Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Mastra npm Packages Compromised in Supply Chain Attack

Mastra npm Packages Compromised in Supply Chain Attack

Posted on June 17, 2026 By CWS

In a notable security breach, 144 npm packages linked to the Mastra namespace, a widely used framework for developing artificial intelligence (AI) applications, have been compromised. This incident, identified as a software supply chain attack and named ‘easy-day-js’, was revealed by security firms including JFrog, SafeDep, Socket, and StepSecurity.

Hijacked Account Leads to Mass Publication

The breach occurred when an npm account named ‘ehindero’ was used to publish over 140 malicious packages within a brief period on June 17, 2026. The packages, although not directly containing harmful code, were compromised through the introduction of a third-party library called ‘easy-day-js’. Initially published as a clean package on June 16, 2026, malicious alterations were made the following day by the npm user ‘sergey2016’.

This ‘easy-day-js’ library executes an obfuscated payload during the installation phase, acting as a dropper for a secondary harmful payload sourced from a remote server (‘23.254.164[.]92’). The payload operates as a background process, erasing itself post-execution to avoid detection.

Cross-Platform Information Theft

The ultimate goal of the attack is to deploy an information-stealing malware capable of accessing browser histories, data from over 160 cryptocurrency wallet extensions, and establishing persistence across multiple operating systems including Windows, macOS, and Linux. The stolen data is then sent to a command-and-control server (‘23.254.164[.]123’).

SafeDep’s analysis reveals that ‘easy-day-js’ is a modified version of the ‘dayjs’ library, integrating a crypto-stealing remote access trojan. The attackers capitalized on a lapse in security by hijacking the account of a legitimate former contributor, whose access was not revoked. Npm has since removed the compromised versions from major packages and reverted their updates.

Security Measures and Impact

Mastra usually ensures the authenticity of its releases through npm’s trusted publisher system, which includes SLSA provenance attestations. However, the attack was facilitated by the use of a personal token, bypassing these security measures. This incident highlights the need for more stringent security policies, such as npm audit signatures or enforced attestations, which could prevent unauthorized publications.

Organizations that have installed the affected packages, including the highly downloaded ‘@mastra/core’, are advised to revert to safe versions, update credentials, and conduct thorough security audits. The attack’s reach is significant, given the popularity of these packages, posing a substantial risk to systems that executed the compromised code during installation.

This incident serves as a critical reminder of the vulnerabilities present in software supply chains, emphasizing the importance of robust security protocols to safeguard against such attacks in the future.

The Hacker News Tags:AI applications, Cryptocurrency, Cybersecurity, JavaScript, Malware, Mastra, NPM, Software Security, supply chain attack, TypeScript

Post navigation

Previous Post: AIRecon Revolutionizes Offline Penetration Testing
Next Post: Exploited Vulnerabilities in Joomla and LiteSpeed Uncovered

Related Posts

Salesforce Patches Critical ForcedLeak Bug Exposing CRM Data via AI Prompt Injection Salesforce Patches Critical ForcedLeak Bug Exposing CRM Data via AI Prompt Injection The Hacker News
Wormable AirPlay Flaws Enable Zero-Click RCE on Apple Devices via Public Wi-Fi Wormable AirPlay Flaws Enable Zero-Click RCE on Apple Devices via Public Wi-Fi The Hacker News
Zero-Click AI Vulnerability Exposes Microsoft 365 Copilot Data Without User Interaction Zero-Click AI Vulnerability Exposes Microsoft 365 Copilot Data Without User Interaction The Hacker News
Microsoft 365 Device Code Phishing Targets Over 340 Organizations Microsoft 365 Device Code Phishing Targets Over 340 Organizations The Hacker News
Fake OpenAI Repo Delivers Malware on Hugging Face Fake OpenAI Repo Delivers Malware on Hugging Face The Hacker News
Unpatched Versa Concerto Flaws Let Attackers Escape Docker and Compromise Host Unpatched Versa Concerto Flaws Let Attackers Escape Docker and Compromise Host The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft to Address ‘RoguePlanet’ Security Flaw in Defender
  • JetBrains Plugins Exploit AI API Keys; Chrome Extensions Leak AI Chats
  • Urgent Chrome Update Fixes Critical Security Flaws
  • Oracle Releases June Security Patch with 245 Fixes
  • LiteLLM Flaw Allows Authentication Bypass via Host Header

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft to Address ‘RoguePlanet’ Security Flaw in Defender
  • JetBrains Plugins Exploit AI API Keys; Chrome Extensions Leak AI Chats
  • Urgent Chrome Update Fixes Critical Security Flaws
  • Oracle Releases June Security Patch with 245 Fixes
  • LiteLLM Flaw Allows Authentication Bypass via Host Header

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark