News Radar RSS

144 Mastra npm Packages Compromised via Hijacked Contributor Account

The Hacker News Cybersecurity Score 6/10

Summary

As many as 144 npm packages associated with the Mastra namespace ("@mastra/*"), a popular open-source JavaScript and TypeScript framework for building artificial intelligence (AI) applications, have been compromised as part of a software supply chain attack codenamed easy-day-js, per findings from Endor Labs, JFrog, SafeDep, Socket, and StepSecurity. "A single npm account (ehindero)

SecurityThreat Intel

News Radar provides aggregated summaries. Full content and copyright remain with the original publisher.