CybersecurityVerified Users Only
145 Mastra npm Packages Compromised via Hijacked Contributor Account
The Hacker NewsยทJune 17, 2026ยท1 min read
As many as 145 npm packages associated with the Mastra namespace ("@mastra/*"), a popular open-source JavaScript and TypeScript framework for building artificial intelligence (AI) applications, have been compromised as part of a software supply chain attack codenamed easy-day-js, per findings from Endor Labs, JFrog, OX Security, SafeDep, Socket, StepSecurity, and Synk. "A single npm account (
Read full article on The Hacker News โShare this article
Follow broker incidents, regulatory actions & market intelligence
Stay ahead with CLEAREX.MARKET
View all intelligence โ