Mastra npm Scope Takeover: 143 Packages Drop a RAT

2026-06-17 Safe Dep

https://safedep.io/mastra-npm-scope-takeover-supply-chain-attack/

Thumbnail for Mastra npm Scope Takeover: 143 Packages Drop a RAT

An attacker reused a dormant former Mastra contributor npm account to republish 143 @mastra packages on June 17, 2026, adding a dependency on easy-day-js that resolved to a malicious postinstall version. The dropper fetched a second-stage Node RAT from Hostwinds infrastructure, installed persistence across macOS, Linux, and Windows, and targeted browser profiles for cryptocurrency wallet extensions and other host data. SafeDep did not confirm attribution, but noted close tradecraft overlap with the Axios npm compromise attributed by Microsoft to Sapphire Sleet.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN hwsrv-1327785.hostwindsdns.com 2026-06-17 2026-06-18
DOMAIN hwsrv-1327786.hostwindsdns.com 2026-06-17 2026-06-18
HASH 4a8860240e4231c3a74c81949be655a… 2026-06-17 2026-06-18
HASH 221c45a790dec2a296af57969e1165a… 2026-06-16 2026-06-18
URL https://23.254.164.92:8000/upda… 2026-06-16 2026-06-18
IPv4 23.254.164.123 2026-06-16 2026-06-18
IPv4 23.254.164.92 2026-06-16 2026-06-18
URL https://23.254.164.123/49890878 2026-06-17 2026-06-17
HASH ae70dd4f6bc0d1c8c2848e4e6b51934… 2026-06-17 2026-06-17

Related Reports

« Back