{"id":1343,"date":"2026-06-17T07:49:07","date_gmt":"2026-06-17T07:49:07","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1343"},"modified":"2026-06-17T07:49:07","modified_gmt":"2026-06-17T07:49:07","slug":"144-mastra-npm-packages-compromised-via-hijacked-contributor-account","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1343","title":{"rendered":"144 Mastra npm Packages Compromised via Hijacked Contributor Account"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jun 17, 2026<\/span><\/span><span class=\"p-tags\">Malware \/ Cryptocurrency<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiKLWn0zHFuJ8rkb2bqILIyAGxt_-VJ13Ytmv1TRWtGJkI6Rva5Oag5LdLasE2rmenokuRvoEI2wH0Ayfe_P4_5q1Qc5FQ2MrQgUHrgD9wY6DTlYugAtj8CP7Fh0OPjKkU5LbeRKWvPEh0Ol0CmLTe4QVayeZiNlVFvU7MO5tWl-b8Lbn80hKd45q9Z1yOd\/s1700-e365\/npms.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>As many as 144 npm packages associated with the <a href=\"https:\/\/mastra.ai\/\">Mastra<\/a> namespace (\u00ab@mastra\/*\u00bb), a popular open-source JavaScript and TypeScript framework for building artificial intelligence (AI) applications, have been compromised as part of a software supply chain attack codenamed <b>easy-day-js<\/b>, per findings from <a href=\"https:\/\/research.jfrog.com\/post\/easy-day-js\/\">JFrog<\/a>, <a href=\"https:\/\/safedep.io\/mastra-npm-scope-takeover-supply-chain-attack\/\">SafeDep<\/a>, <a href=\"https:\/\/socket.dev\/blog\/mastra-npm-packages-compromised\">Socket<\/a>, and <a href=\"https:\/\/www.stepsecurity.io\/blog\/mastra-npm-packages-compromised-using-easy-day-js\">StepSecurity<\/a>.<\/p>\n<p>\u00abA single npm account (ehindero) mass-published more than 140 malicious packages across the Mastra scope within a short window on 2026-06-17,\u00bb Socket said.<\/p>\n<p>The infected packages themselves do not include malicious code. Instead, it&#8217;s introduced by means of a third-party library named \u00abeasy-day-js\u00bb that has been added to each package&#8217;s dependency list. The JavaScript library was published by an npm user called \u00absergey2016\u00bb on June 16, 2026, at 7:05 a.m. UTC as a clean, fully functional copy, with the malicious changes introduced on June 17, 2026, at 1:01 a.m. UTC.<\/p>\n<p>The \u00abeasy-day-js\u00bb package launches an obfuscated payload that&#8217;s fired during a postinstall hook, which acts as a dropper or loader for a second-stage payload retrieved from attacker-controlled infrastructure (\u00ab23.254.164[.]92\u00bb) after disabling TLS certificate validation.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The payload is then executed as a detached background process, following which the loader takes steps to erase itself to minimize the forensic trail.<\/p>\n<p>The final stage is a cross-platform information stealer that can harvest browser history, store data from over 160 cryptocurrency wallet browser extensions, install persistence across Windows, macOS, and Linux, and exfiltrate the captured information to the C2 server (\u00ab23.254.164[.]123\u00bb).<\/p>\n<p>In its analysis, SafeDep described \u00abeasy-day-js\u00bb as a clone of the \u00abdayjs\u00bb date library that downloads and runs a cryptocurrency-stealing remote access trojan. The attackers behind the campaign are said to have hijacked the \u00abehindero\u00bb account, a legitimate former Mastra contributor whose scope access was never revoked. Npm has since pulled the malicious versions from the highest-profile packages and reverted their latest tag.<\/p>\n<table cellpadding=\"0\" cellspacing=\"0\" class=\"tr-caption-container\" style=\"float: left;\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgF9cwWgnA3fbURa67fpzPNtRuAAoA4UDsP3SVRtp8xc64DTbOZbS6ULj9johyphenhyphenOCJGSJRcblznnaCzcxCM4Puq1OXTjcbyZLsRZxJmVoiuI-4exlxufoVpnDUWeB3Dl-hfMMPzAGuBn_Skr-GG5b7fhq1Eb7tqcxyVYmTVxbBngRs8lBEaWcUvfHqdo8DSl\/s1700-e365\/StepSecurity.jpg\" style=\"clear: left; display: block; margin-left: auto; margin-right: auto;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgF9cwWgnA3fbURa67fpzPNtRuAAoA4UDsP3SVRtp8xc64DTbOZbS6ULj9johyphenhyphenOCJGSJRcblznnaCzcxCM4Puq1OXTjcbyZLsRZxJmVoiuI-4exlxufoVpnDUWeB3Dl-hfMMPzAGuBn_Skr-GG5b7fhq1Eb7tqcxyVYmTVxbBngRs8lBEaWcUvfHqdo8DSl\/s1700-e365\/StepSecurity.jpg\" alt=\"\" border=\"0\" data-original-height=\"1170\" data-original-width=\"1496\"\/><\/a><\/td>\n<\/tr>\n<tr>\n<td class=\"tr-caption\" style=\"text-align: center;\">Image Source: StepSecurity<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u00abMastra ships its real releases from CI through npm&#8217;s trusted publisher flow, and each one carries SLSA provenance attestations,\u00bb SafeDep said. \u00abThe attacker pushed the malicious versions from a personal token and dropped the provenance.\u00bb<\/p>\n<p>\u00abThe same fingerprint repeats across the whole scope. Mastra generated provenance on CI publishes but did not require it, so a standard npm token could still publish without attestations. A signature-verifying install (npm audit signatures, or a policy that requires attestations) would have rejected every package in this wave.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/vpn-threat-report-m\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhFlTC7RrRZGiFAgASS0noWSL0qsQGFVp8-Hvuw9yp3X3VKRuTcb5SsPX09wJzrdIM6pu1_5lS4EeZp7Sx4iYBpNJkrGnpr08yyaS1HQ5_5TxaCsP6O0OtHNuOkesn6CbNjao1GPulCJk-uljYMSfMZfBYNrngpe669t7jlRn1FqiEnXhsFD1WVkpaYIVgh\/s728-e100\/ai-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Any workstation, CI runner, or build environment that installed the affected versions should be treated as potentially compromised. It&#8217;s advised to roll back to a safe version, rotate any credentials, and audit the hosts for any artifacts linked to the campaign.<\/p>\n<p>\u00abThe affected packages include @mastra\/core, which receives more than 918K weekly npm downloads, giving this campaign a large potential blast radius,\u00bb Socket said. \u00abBecause the payload executes during installation, systems may be exposed before developers import or use the package.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jun 17, 2026Malware \/ Cryptocurrency As many as 144 npm packages associated with the Mastra namespace (\u00ab@mastra\/*\u00bb), a popular open-source JavaScript and TypeScript framework for building artificial intelligence (AI)&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1344,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[573,227,2075,804,2074,39,35],"class_list":["post-1343","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-account","tag-compromised","tag-contributor","tag-hijacked","tag-mastra","tag-npm","tag-packages"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1343","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1343"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1343\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1344"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1343"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1343"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1343"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}