Shares tags: SupplyChain, NPM, T1195 • Published within a week
INCIDENT REPORT: 2026-06-16: Mastra hit by supply-chain attack
2026-06-17 • Mastra •
A compromised Mastra maintainer account was used to publish 116 malicious npm packages, mostly under the `@mastra/` namespace, with a postinstall script designed to exfiltrate credentials and remove itself. Mastra identified the attack the evening of June 16, 2026, coordinated with npm and Socket Security, unpublished or deprecated the affected versions, and released safe replacements. The compromise originated from social phishing via a compromised LinkedIn account, after which Mastra removed npm token bypass across its packages despite already requiring MFA.
Related Reports
Shares tags: SupplyChain, NPM, T1195 • Published within a week
2026-06-17 •
46% Match
#SupplyChain
#NPM
#T1082
#T1059.007
#T1027
#T1552
#T1057
#T1195
#T1105
#T1195.001
#T1547
#T1518
#Mastra
Shares tags: SupplyChain, NPM, T1195 • Published within a week
Shares tags: SupplyChain, NPM, T1195 • Published within a week
Shares tags: SupplyChain, NPM, Mastra • Published within a week
Shares tags: SupplyChain, NPM, Mastra • Published within a week