A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope
CYBERSECURITY FEATURED ANALYSIS

A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope

SOURCE

Blog RSS Feed | Snyk

DATE

READ

1 min read

A dormant contributor account was used to republish the entire @mastra npm scope, each injected with a single dependency, easy-day-js, that drops a cross-platform cryptocurrency stealer. Here is how the attack worked, …

A dormant contributor account was used to republish the entire @mastra npm scope, each injected with a single dependency, easy-day-js, that drops a cross-platform cryptocurrency stealer. Here is how the attack worked, how to check exposure, and how to remediate.