140+ Mastra npm Packages Compromised in Coordinated Supply Chain Attack

2026-06-17 Socket

https://socket.dev/blog/mastra-npm-packages-compromised

Thumbnail for 140+ Mastra npm Packages Compromised in Coordinated Supply Chain Attack

A compromised Mastra npm release wave added the typosquatted dependency `easy-day-js`, whose `postinstall` hook executed during dependency installation and pulled a second-stage Node.js implant from attacker-controlled infrastructure. The implant installed persistence across Windows, macOS, and Linux, collected browser history and cryptocurrency wallet extension inventory, and supported operator-delivered Node or shell tasking. Socket reported 141 affected `@mastra/*` packages, including high-download packages such as `@mastra/core`, making developer workstations, CI runners, and build systems that installed affected versions potential compromise points. Remediation centers on treating affected hosts as compromised, removing persistence and package artifacts, clearing caches, rebuilding from clean environments, and rotating developer and CI/CD credentials.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN hwsrv-1327785.hostwindsdns.com 2026-06-17 2026-06-18
DOMAIN hwsrv-1327786.hostwindsdns.com 2026-06-17 2026-06-18
HASH 221c45a790dec2a296af57969e1165a… 2026-06-16 2026-06-18
URL https://23.254.164.92:8000/upda… 2026-06-16 2026-06-18
IPv4 23.254.164.123 2026-06-16 2026-06-18
IPv4 23.254.164.92 2026-06-16 2026-06-18
HASH 9570f77a5e1511869f4e554e7166df9… 2026-06-17 2026-06-17
HASH cdec8b20338beb708b5be8d3d7a3041… 2026-06-17 2026-06-17
HASH c38954e85bf5433e61e7c8f42303366… 2026-06-17 2026-06-17
URL https://23.254.164.123:443/4989… 2026-06-17 2026-06-17
HASH b122a9873bedf145ae2a7fd024b5f30… 2026-06-17 2026-06-17

Related Reports

« Back