Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

144 Mastra npm Packages Compromised via Hijacked Contributor Account

The Hacker News by The Hacker News
June 17, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananJun 17, 2026Malware / Cryptocurrency

As many as 144 npm packages associated with the Mastra namespace (“@mastra/*”), a popular open-source JavaScript and TypeScript framework for building artificial intelligence (AI) applications, have been compromised as part of a software supply chain attack codenamed easy-day-js, per findings from JFrog, SafeDep, Socket, and StepSecurity.

“A single npm account (ehindero) mass-published more than 140 malicious packages across the Mastra scope within a short window on 2026-06-17,” Socket said.

The infected packages themselves do not include malicious code. Instead, it’s introduced by means of a third-party library named “easy-day-js” that has been added to each package’s dependency list. The JavaScript library was published by an npm user called “sergey2016” on June 16, 2026, at 7:05 a.m. UTC as a clean, fully functional copy, with the malicious changes introduced on June 17, 2026, at 1:01 a.m. UTC.

The “easy-day-js” package launches an obfuscated payload that’s fired during a postinstall hook, which acts as a dropper or loader for a second-stage payload retrieved from attacker-controlled infrastructure (“23.254.164[.]92”) after disabling TLS certificate validation.

The payload is then executed as a detached background process, following which the loader takes steps to erase itself to minimize the forensic trail.

The final stage is a cross-platform information stealer that can harvest browser history, store data from over 160 cryptocurrency wallet browser extensions, install persistence across Windows, macOS, and Linux, and exfiltrate the captured information to the C2 server (“23.254.164[.]123”).

In its analysis, SafeDep described “easy-day-js” as a clone of the “dayjs” date library that downloads and runs a cryptocurrency-stealing remote access trojan. The attackers behind the campaign are said to have hijacked the “ehindero” account, a legitimate former Mastra contributor whose scope access was never revoked. Npm has since pulled the malicious versions from the highest-profile packages and reverted their latest tag.

Image Source: StepSecurity

“Mastra ships its real releases from CI through npm’s trusted publisher flow, and each one carries SLSA provenance attestations,” SafeDep said. “The attacker pushed the malicious versions from a personal token and dropped the provenance.”

“The same fingerprint repeats across the whole scope. Mastra generated provenance on CI publishes but did not require it, so a standard npm token could still publish without attestations. A signature-verifying install (npm audit signatures, or a policy that requires attestations) would have rejected every package in this wave.”

Any workstation, CI runner, or build environment that installed the affected versions should be treated as potentially compromised. It’s advised to roll back to a safe version, rotate any credentials, and audit the hosts for any artifacts linked to the campaign.

“The affected packages include @mastra/core, which receives more than 918K weekly npm downloads, giving this campaign a large potential blast radius,” Socket said. “Because the payload executes during installation, systems may be exposed before developers import or use the package.”



Source link

The Hacker News

The Hacker News

Next Post
China pushes for AI safety as G7 summit wraps up without Beijing

China pushes for AI safety as G7 summit wraps up without Beijing

Recommended.

Alibaba-backed startup Moonshot AI’s valuation is up 0 million, sources say, after its rivals IPO in Hong Kong

Alibaba-backed startup Moonshot AI’s valuation is up $500 million, sources say, after its rivals IPO in Hong Kong

January 19, 2026
Claude Code Security and Magecart: Getting the Threat Model Right

Claude Code Security and Magecart: Getting the Threat Model Right

March 18, 2026

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

May 1, 2026
30 Notable IT Executive Moves: April 2026

30 Notable IT Executive Moves: April 2026

May 11, 2026
The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

The 50 Coolest Software-Defined Storage Vendors: The 2026 Storage 100

April 13, 2026
The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

The 15 Hottest AI Data And Analytics Companies: The 2026 CRN AI 100

April 6, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio