A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope

2026-06-16 Snyk

https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope/

Thumbnail for A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope

A stale former contributor npm account was used to republish the Mastra npm scope with a malicious `easy-day-js` dependency that executed at install time. The dropper disabled TLS validation, fetched a second-stage payload from a raw IP, and installed a cross-platform cryptocurrency wallet stealer and RAT with persistence on macOS, Linux, and Windows. Snyk observed similarities to the earlier Axios npm compromise attributed to Sapphire Sleet/BlueNoroff, but stated that attribution for the Mastra incident itself is unconfirmed. Affected users are advised to treat installs during the June 17, 2026 exposure window as host-compromise events, rotate credentials, check for persistence artifacts, and upgrade to clean Mastra releases.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 221c45a790dec2a296af57969e1165a… 2026-06-16 2026-06-18
URL https://23.254.164.92:8000/upda… 2026-06-16 2026-06-18
IPv4 23.254.164.123 2026-06-16 2026-06-18
IPv4 23.254.164.92 2026-06-16 2026-06-18
EMAIL [email protected] 2026-06-16 2026-06-17

Related Reports

« Back