
CYBERSECURITY
FEATURED ANALYSIS
A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope
SOURCE
Blog RSS Feed | Snyk
DATE
READ
1 min read
A dormant contributor account was used to republish the entire @mastra npm scope, each injected with a single dependency, easy-day-js, that drops a cross-platform cryptocurrency stealer. Here is how the attack worked, …
A dormant contributor account was used to republish the entire @mastra npm scope, each injected with a single dependency, easy-day-js, that drops a cross-platform cryptocurrency stealer. Here is how the attack worked, how to check exposure, and how to remediate.