Mastra Attack Targets Crypto, Password Managers, Authenticators, and Zapier

2026-06-18 OSM

https://opensourcemalware.com/blog/mastra-npm-malware

Thumbnail for Mastra Attack Targets Crypto, Password Managers, Authenticators, and Zapier

A compromised dormant maintainer account republished more than 140 Mastra npm packages with a malicious dependency on `easy-day-js`, a clean-then-armed typosquat that installed a two-stage JavaScript backdoor. The payload stole browser history and data from 166 crypto wallet, password-manager, authenticator, and Zapier extensions, then provided cross-platform persistence, beaconing, fallback DGA domains, and remote code execution. The author found strong overlap with the Axios npm compromise that Microsoft attributed to Lazarus Group, including Hostwinds infrastructure, postinstall delivery, disabled TLS validation, self-deletion, and crypto-focused theft, but cautioned that Mastra attribution remains unconfirmed.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://23.254.164.123:8000/upd… 2026-06-20 2026-06-20
DOMAIN hwsrv-1327785.hostwindsdns.com 2026-06-20 2026-06-20
DOMAIN hwsrv-1327786.hostwindsdns.com 2026-06-20 2026-06-20
HASH c18fd75526533dfc90e91e2fb80effaf 2026-06-20 2026-06-20
HASH 4a8860240e4231c3a74c81949be655a… 2026-06-20 2026-06-20
URL https://23.254.164.92:8000/upda… 2026-06-20 2026-06-20
IPv4 23.254.164.123 2026-06-20 2026-06-20
IPv4 23.254.164.92 2026-06-20 2026-06-20

Related Actors

Related Reports

« Back