Dispatch
144 @mastra npm Packages Backdoored in 88-Minute Supply-Chain Attack on AI Framework
On June 17 an attacker hijacked a stale contributor account ('ehindero') and republished 142 packages under the @mastra npm scope in an automated 88-minute run, injecting a typosquatted 'easy-day-js' dependency. The postinstall payload disabled TLS verification, fetched a second-stage C2 binary, and harvested browser data plus credentials from 166 crypto-wallet extensions; @mastra/core alone sees ~918K weekly downloads, so blast radius is large. Teams building AI apps on Mastra should roll back to pre-incident versions and rotate npm, GitHub, cloud, and LLM API tokens immediately.
↳ Follow the thread