Mastra npm Org Compromised: Multiple Packages Trojanized to Drop a Remote Payload via easy-day-js
Blog post from Endor Labs
In a recent security incident, an attacker hijacked an account of a Mastra maintainer and used it to modify the entire @mastra catalog over a brief 27-minute period. They inserted a misleading dependency, easy-day-js, a counterfeit of the popular dayjs library, into each package without altering the original Mastra code. This dependency, while appearing benign, executes a harmful script during installation that disables TLS certificate validation and fetches a secondary payload. This sweeping attack affected 116 packages and was made possible by the compromised account having organization-wide publishing rights. The incident highlights the vulnerability of widely used open-source software like Mastra, which is crucial for building AI applications and is downloaded millions of times monthly. The malicious activity was cleverly concealed, as the Mastra packages remained unmodified externally, with the harmful code residing a level deeper. Detection relied on identifying the altered dependency line in package.json, and the attacker had pre-staged a clean decoy version of easy-day-js before deploying the weaponized one. This breach underscores the importance of enforcing provenance and scrutinizing dependency changes to safeguard against similar threats in the future.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| MCP | 3 | 7,668 | 844 | 209 | +8% |
| OpenTelemetry | 2 | 968 | 178 | 57 | +2% |
| Observability | 1 | 4,230 | 776 | 198 | +24% |
| RAG | 1 | 1,000 | 260 | 106 | -52% |
| Real-time | 1 | 5,758 | 1,361 | 266 | +0% |
| Secrets Management | 1 | 2,515 | 393 | 134 | +17% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.