Mastra @mastra/* npm packages hit by network compromise
Incident
Summary
Hide ▲
Show ▼
Mastra @mastra/* npm packages were compromised in a software supply chain attack that spread through the namespace on 2026-06-17. Microsoft now attributes the activity to Sapphire Sleet (BlueNoroff), saying the attackers compromised the npm maintainer account "ehindero" and published malicious updates to more than 140 npm packages in the @mastra scope. The poisoned packages injected easy-day-js, which ran a postinstall hook, disabled TLS certificate verification, contacted attacker-controlled C2 infrastructure, and deployed a cross-platform stealer on Windows, Linux, and macOS. The activity put credentials, API keys, authentication tokens, and cryptocurrency wallets at risk across developer systems, CI runners, and build environments.
Related Happenings
SeasonalInvite eCard phishing campaign targeting Windows and macOS users
Campaign
H score30
First: 15.07.2026 18:00
Last: 15.07.2026 18:00
Sources 1
About this happening:
The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...
SeasonalInvite eCard phishing campaign targeting Windows and macOS users
CampaignAbout this happening: The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...
Jscrambler hit by network compromise
Incident
H score15
First: 13.07.2026 22:44
Last: 13.07.2026 22:44
Sources 1
About this happening:
The Jscrambler npm package suffered an unauthorized publication of a malicious version that exposed developers to infostealer theft risk. The bad release stayed li...
Jscrambler hit by network compromise
IncidentAbout this happening: The Jscrambler npm package suffered an unauthorized publication of a malicious version that exposed developers to infostealer theft risk. The bad release stayed li...
Jscrambler 8.14.0 malicious preinstall infostealer release
Malware Activity
H score9
First: 11.07.2026 20:59
Last: 11.07.2026 20:59
Sources 1
About this happening:
The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...
Jscrambler 8.14.0 malicious preinstall infostealer release
Malware ActivityAbout this happening: The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...
@Injectivelabs/[email protected] wallet-stealing package
Malware Activity
H score30
First: 10.07.2026 20:29
Last: 10.07.2026 20:29
Sources 1
About this happening:
The malicious @injectivelabs/[email protected] package is a wallet-stealing malware activity that can expose private keys and mnemonic seed phrases when library functions...
@Injectivelabs/[email protected] wallet-stealing package
Malware ActivityAbout this happening: The malicious @injectivelabs/[email protected] package is a wallet-stealing malware activity that can expose private keys and mnemonic seed phrases when library functions...
Injective Labs SDK project GitHub repository hit by network compromise
Incident
H score21
First: 09.07.2026 23:10
Last: 09.07.2026 23:10
Sources 1
About this happening:
The Injective Labs SDK project suffered a GitHub repository compromise that let attackers publish a malicious @injectivelabs/sdk-ts v1.20.21 package, putting developer...
Injective Labs SDK project GitHub repository hit by network compromise
IncidentAbout this happening: The Injective Labs SDK project suffered a GitHub repository compromise that let attackers publish a malicious @injectivelabs/sdk-ts v1.20.21 package, putting developer...
Timeline
-
20.06.2026 17:09 2 articles · 25d ago
Microsoft attributes Mastra npm attack to Sapphire Sleet
Attribution UpdateMicrosoft attributed the Mastra AI supply chain attack to Sapphire Sleet, also known as BlueNoroff, and said the attackers compromised the npm maintainer account ehindero, which had publishing privileges across the Mastra package environment. The June 19 update said more than 140 packages in the @mastra scope were modified to inject easy-day-js.
Show sources
- Microsoft links Mastra AI supply chain attack to North Korean hackers — www.bleepingcomputer.com — 20.06.2026 17:09
- Microsoft Attributes Mastra AI Supply Chain Attack to North Korea — www.infosecurity-magazine.com — 22.06.2026 14:30
-
17.06.2026 10:38 2 articles · 28d ago
Mastra @mastra/* npm packages hit by network compromise
Initial DisclosureA hijacked ehindero contributor account mass-published malicious releases across the Mastra npm scope on 2026-06-17. The compromise spread through a dependency on easy-day-js, which was inserted into affected package manifests.
Show sources
- 144 Mastra npm Packages Compromised via Hijacked Contributor Account — thehackernews.com — 17.06.2026 10:38
- 144 Mastra npm Packages Compromised via Hijacked Contributor Account — thehackernews.com — 17.06.2026 10:38