Last updated 1 month ago
Mastra, an open-source JavaScript and TypeScript framework for building AI applications, suffered a software supply chain attack in which 144 npm packages under the @mastra/* namespace were compromised. The incident was publicly disclosed on June 17, 2026, following coordinated findings from Endor Labs, JFrog, SafeDep, Socket, and StepSecurity. The exact discovery date is not stated, and no record count or user population impact is provided.
The attack chain began with the compromise of a single npm account (ehindero), which was used to publish malicious versions of the packages. The campaign, codenamed easy-day-js, leveraged the trusted contributor's access to inject malicious code into the supply chain. No specific CVEs, threat actor attribution, or exfiltrated data types are mentioned; the primary impact is the distribution of malicious code to downstream consumers.
No post-incident developments such as regulatory actions, litigation, ransom payments, or remediation milestones are reported in the article.
Compromised npm contributor account (ehindero) used to publish malicious versions of 144 @mastra/* packages
Sign in to join the discussion.
Company
Industry
Disclosed
Records Affected
Attack Vector