Back to Intel

Intel Node

144 Mastra npm Packages Compromised via Hijacked Contributor Account

lowadvisory2026-06-17T07:38:24+00:00source excerpt

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

As many as 144 npm packages associated with the Mastra namespace ("@mastra/*"), a popular open-source JavaScript and TypeScript framework for building artificial intelligence (AI) applications, have been compromised as part of a software supply chain attack codenamed easy-day-js, per findings from JFrog, SafeDep, Socket, and StepSecurity.

Read Original Source