« 2026

387 reports

2026-06-17 • Microsoft

Sapphire Sleet compromised the Mastra npm ecosystem by taking over the `ehindero` maintainer account and injecting the malicious `easy-day-js` typosquat into more than 140 `mastra` and `@mastra` packages. The weaponized package ran a postinstall dropper t…

#SupplyChain #NPM #SapphireSleet #T1071.001 #T1195.002 #T1059.007 #T1027 #T1547.001 #T1059.001 #T1105 #T1055 #T1562.001 #T1543.003 #Mastra