Mastra Attack Targets Crypto, Password Managers, Authenticators, and Zapier
2026-06-18 • OSM •
A compromised dormant maintainer account republished more than 140 Mastra npm packages with a malicious dependency on `easy-day-js`, a clean-then-armed typosquat that installed a two-stage JavaScript backdoor. The payload stole browser history and data from 166 crypto wallet, password-manager, authenticator, and Zapier extensions, then provided cross-platform persistence, beaconing, fallback DGA domains, and remote code execution. The author found strong overlap with the Axios npm compromise that Microsoft attributed to Lazarus Group, including Hostwinds infrastructure, postinstall delivery, disabled TLS validation, self-deletion, and crypto-focused theft, but cautioned that Mastra attribution remains unconfirmed.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://23.254.164.123:8000/upd… | 2026-06-20 | 2026-06-20 |
| DOMAIN | hwsrv-1327785.hostwindsdns.com | 2026-06-20 | 2026-06-20 |
| DOMAIN | hwsrv-1327786.hostwindsdns.com | 2026-06-20 | 2026-06-20 |
| HASH | c18fd75526533dfc90e91e2fb80effaf | 2026-06-20 | 2026-06-20 |
| HASH | 4a8860240e4231c3a74c81949be655a… | 2026-06-20 | 2026-06-20 |
| URL | https://23.254.164.92:8000/upda… | 2026-06-20 | 2026-06-20 |
| IPv4 | 23.254.164.123 | 2026-06-20 | 2026-06-20 |
| IPv4 | 23.254.164.92 | 2026-06-20 | 2026-06-20 |