Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

Mastra npm Org Compromised: Multiple Packages Trojanized to Drop a Remote Payload via easy-day-js

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Peyton Kennedy
Word Count
2,107
Company Posts That Month
16
Language
English
Hacker News Points
-
Post removed?
No
Summary

In a recent security incident, an attacker hijacked an account of a Mastra maintainer and used it to modify the entire @mastra catalog over a brief 27-minute period. They inserted a misleading dependency, easy-day-js, a counterfeit of the popular dayjs library, into each package without altering the original Mastra code. This dependency, while appearing benign, executes a harmful script during installation that disables TLS certificate validation and fetches a secondary payload. This sweeping attack affected 116 packages and was made possible by the compromised account having organization-wide publishing rights. The incident highlights the vulnerability of widely used open-source software like Mastra, which is crucial for building AI applications and is downloaded millions of times monthly. The malicious activity was cleverly concealed, as the Mastra packages remained unmodified externally, with the harmful code residing a level deeper. Detection relied on identifying the altered dependency line in package.json, and the attacker had pre-staged a clean decoy version of easy-day-js before deploying the weaponized one. This breach underscores the importance of enforcing provenance and scrutinizing dependency changes to safeguard against similar threats in the future.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
MCP 3 7,668 844 209 +8%
OpenTelemetry 2 968 178 57 +2%
Observability 1 4,230 776 198 +24%
RAG 1 1,000 260 106 -52%
Real-time 1 5,758 1,361 266 +0%
Secrets Management 1 2,515 393 134 +17%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.