Find notable cyber news and cases, enriched with sources, timelines, and signals.

Mastra @mastra/* npm packages hit by network compromise

Incident
First reported
Last updated
Happening score
H score 47
3 unique sources, 3 articles

Summary

Hide ▲

Mastra @mastra/* npm packages were compromised in a software supply chain attack that spread through the namespace on 2026-06-17. Microsoft now attributes the activity to Sapphire Sleet (BlueNoroff), saying the attackers compromised the npm maintainer account "ehindero" and published malicious updates to more than 140 npm packages in the @mastra scope. The poisoned packages injected easy-day-js, which ran a postinstall hook, disabled TLS certificate verification, contacted attacker-controlled C2 infrastructure, and deployed a cross-platform stealer on Windows, Linux, and macOS. The activity put credentials, API keys, authentication tokens, and cryptocurrency wallets at risk across developer systems, CI runners, and build environments.

Related Happenings

SeasonalInvite eCard phishing campaign targeting Windows and macOS users

Campaign
H score30 First: 15.07.2026 18:00 Last: 15.07.2026 18:00 Sources 1

About this happening: The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards...

Jscrambler hit by network compromise

Incident
H score15 First: 13.07.2026 22:44 Last: 13.07.2026 22:44 Sources 1

About this happening: The Jscrambler npm package suffered an unauthorized publication of a malicious version that exposed developers to infostealer theft risk. The bad release stayed li...

Jscrambler 8.14.0 malicious preinstall infostealer release

Malware Activity
H score9 First: 11.07.2026 20:59 Last: 11.07.2026 20:59 Sources 1

About this happening: The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on ...

@Injectivelabs/[email protected] wallet-stealing package

Malware Activity
H score30 First: 10.07.2026 20:29 Last: 10.07.2026 20:29 Sources 1

About this happening: The malicious @injectivelabs/[email protected] package is a wallet-stealing malware activity that can expose private keys and mnemonic seed phrases when library functions...

Injective Labs SDK project GitHub repository hit by network compromise

Incident
H score21 First: 09.07.2026 23:10 Last: 09.07.2026 23:10 Sources 1

About this happening: The Injective Labs SDK project suffered a GitHub repository compromise that let attackers publish a malicious @injectivelabs/sdk-ts v1.20.21 package, putting developer...

Timeline

  1. 20.06.2026 17:09 2 articles · 25d ago

    Microsoft attributes Mastra npm attack to Sapphire Sleet

    Attribution Update

    Microsoft attributed the Mastra AI supply chain attack to Sapphire Sleet, also known as BlueNoroff, and said the attackers compromised the npm maintainer account ehindero, which had publishing privileges across the Mastra package environment. The June 19 update said more than 140 packages in the @mastra scope were modified to inject easy-day-js.

    Show sources
  2. 17.06.2026 10:38 2 articles · 28d ago

    Mastra @mastra/* npm packages hit by network compromise

    Initial Disclosure

    A hijacked ehindero contributor account mass-published malicious releases across the Mastra npm scope on 2026-06-17. The compromise spread through a dependency on easy-day-js, which was inserted into affected package manifests.

    Show sources