National Cyber Warfare Foundation (NCWF)

Mastra Packages Trojanized with Malicious Dependency (Campaign)


0 user ratings
2026-06-28 15:11:22
milo
Attacks
On 17 June 2026, attackers compromised a maintainer account associated with the Mastra npm organization and used it to republish 116 packages over a 27-minute period. Rather than modifying Mastra’s source code directly, the threat actor injected a malicious dependency, easy-da...

On 17 June 2026, attackers compromised a maintainer account associated with the Mastra npm organization and used it to republish 116 packages over a 27-minute period. Rather than modifying Mastra’s source code directly, the threat actor injected a malicious dependency, easy-da...

Source: Wiz
Source Link: https://threats.wiz.io/all-incidents/mastra-packages-trojanized-with-malicious-dependency


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Attacks



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.