Wednesday, 17 June 2026

144 Mastra npm Packages Compromised via Hijacked Contributor Account

iT4iNT SERVER As many as 144 npm packages associated with the Mastra namespace ("@mastra/*"), a popular open-source JavaScript and TypeScript framework for building artificial intelligence (AI) applications, have been compromised as part of a software supply chain attack codenamed easy-day-js, per findings from JFrog, SafeDep, Socket, and StepSecurity.

"A single npm account (ehindero) mass-published more VDS VPS Cloud


http://dlvr.it/TT4kpH

No comments:

Post a Comment

The Top 10 Attack Surface Exposures in 2026

iT4iNT SERVER Breaches don't always start with a zero-day. An exposed admin panel can get brute-forced, or credentials reused from a pre...