A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope

2026-06-16 Snyk

https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope/

Thumbnail for A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope

A stale former contributor npm account was used to republish the Mastra npm scope with a malicious `easy-day-js` dependency that executed at install time. The dropper disabled TLS validation, fetched a second-stage payload from a raw IP, and installed a cross-platform cryptocurrency wallet stealer and RAT with persistence on macOS, Linux, and Windows. Snyk observed similarities to the earlier Axios npm compromise attributed to Sapphire Sleet/BlueNoroff, but stated that attribution for the Mastra incident itself is unconfirmed. Affected users are advised to treat installs during the June 17, 2026 exposure window as host-compromise events, rotate credentials, check for persistence artifacts, and upgrade to clean Mastra releases.

Indicators of Compromise

Type Value First Seen Last Seen
HASH c18fd75526533dfc90e91e2fb80effaf 2026-06-20 2026-06-20
EMAIL [email protected] 2026-06-20 2026-06-20
URL https://23.254.164.92:8000/upda… 2026-06-20 2026-06-20
IPv4 23.254.164.123 2026-06-20 2026-06-20
IPv4 23.254.164.92 2026-06-20 2026-06-20

Related Reports

« Back