News Radar RSS

A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope

Snyk Blog Cybersecurity Score 6/10

Summary

A dormant contributor account was used to republish the entire @mastra npm scope, each injected with a single dependency, easy-day-js, that drops a cross-platform cryptocurrency stealer. Here is how the attack worked, how to check exposure, and how to remediate.

SecurityDeveloper Tools

News Radar provides aggregated summaries. Full content and copyright remain with the original publisher.