Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Mastra npm Packages Compromised in Supply Chain Attack

Mastra npm Packages Compromised in Supply Chain Attack

Posted on June 17, 2026 By CWS

In a notable security breach, 144 npm packages linked to the Mastra namespace, a widely used framework for developing artificial intelligence (AI) applications, have been compromised. This incident, identified as a software supply chain attack and named ‘easy-day-js’, was revealed by security firms including JFrog, SafeDep, Socket, and StepSecurity.

Hijacked Account Leads to Mass Publication

The breach occurred when an npm account named ‘ehindero’ was used to publish over 140 malicious packages within a brief period on June 17, 2026. The packages, although not directly containing harmful code, were compromised through the introduction of a third-party library called ‘easy-day-js’. Initially published as a clean package on June 16, 2026, malicious alterations were made the following day by the npm user ‘sergey2016’.

This ‘easy-day-js’ library executes an obfuscated payload during the installation phase, acting as a dropper for a secondary harmful payload sourced from a remote server (‘23.254.164[.]92’). The payload operates as a background process, erasing itself post-execution to avoid detection.

Cross-Platform Information Theft

The ultimate goal of the attack is to deploy an information-stealing malware capable of accessing browser histories, data from over 160 cryptocurrency wallet extensions, and establishing persistence across multiple operating systems including Windows, macOS, and Linux. The stolen data is then sent to a command-and-control server (‘23.254.164[.]123’).

SafeDep’s analysis reveals that ‘easy-day-js’ is a modified version of the ‘dayjs’ library, integrating a crypto-stealing remote access trojan. The attackers capitalized on a lapse in security by hijacking the account of a legitimate former contributor, whose access was not revoked. Npm has since removed the compromised versions from major packages and reverted their updates.

Security Measures and Impact

Mastra usually ensures the authenticity of its releases through npm’s trusted publisher system, which includes SLSA provenance attestations. However, the attack was facilitated by the use of a personal token, bypassing these security measures. This incident highlights the need for more stringent security policies, such as npm audit signatures or enforced attestations, which could prevent unauthorized publications.

Organizations that have installed the affected packages, including the highly downloaded ‘@mastra/core’, are advised to revert to safe versions, update credentials, and conduct thorough security audits. The attack’s reach is significant, given the popularity of these packages, posing a substantial risk to systems that executed the compromised code during installation.

This incident serves as a critical reminder of the vulnerabilities present in software supply chains, emphasizing the importance of robust security protocols to safeguard against such attacks in the future.

The Hacker News Tags:AI applications, Cryptocurrency, Cybersecurity, JavaScript, Malware, Mastra, NPM, Software Security, supply chain attack, TypeScript

Post navigation

Previous Post: AIRecon Revolutionizes Offline Penetration Testing
Next Post: Exploited Vulnerabilities in Joomla and LiteSpeed Uncovered

Related Posts

Microsoft Discloses Exchange Server Flaw Enabling Silent Cloud Access in Hybrid Setups Microsoft Discloses Exchange Server Flaw Enabling Silent Cloud Access in Hybrid Setups The Hacker News
AI Tool Exploited at Thai Finance Ministry AI Tool Exploited at Thai Finance Ministry The Hacker News
Pentagon Labels Anthropic a Supply Chain Risk Amid AI Dispute Pentagon Labels Anthropic a Supply Chain Risk Amid AI Dispute The Hacker News
China-Linked Hackers Exploit Windows Shortcut Flaw to Target European Diplomats China-Linked Hackers Exploit Windows Shortcut Flaw to Target European Diplomats The Hacker News
Cursor AI Code Editor Flaw Enables Silent Code Execution via Malicious Repositories Cursor AI Code Editor Flaw Enables Silent Code Execution via Malicious Repositories The Hacker News
Abuse of Google Play Early Access for Deceptive Apps Abuse of Google Play Early Access for Deceptive Apps The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical cPanel Security Flaw in LiteSpeed Server Fixed
  • Homebrew 7.0.0 Unveils Vulnerability Scanner and Enhanced Security
  • Major Breach at Japan’s Digital Agency Exposes 240,000 Records
  • Critical Cisco Email Gateway Flaw Exploited, CISA Warns
  • Underground AI Service ‘Luciferus’ Promoted by Hackers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical cPanel Security Flaw in LiteSpeed Server Fixed
  • Homebrew 7.0.0 Unveils Vulnerability Scanner and Enhanced Security
  • Major Breach at Japan’s Digital Agency Exposes 240,000 Records
  • Critical Cisco Email Gateway Flaw Exploited, CISA Warns
  • Underground AI Service ‘Luciferus’ Promoted by Hackers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark