Home / Companies / Snyk / Blog / Post Details
Content Deep Dive

A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope

Blog post from Snyk

Post Details
Company
Date Published
Author
Liran Tal and Marian Corneci
Word Count
2,096
Company Posts That Month
18
Language
English
Hacker News Points
-
Post removed?
No
Summary

On June 17, 2026, an attack on the npm package scope @mastra led to the mass republishing of 143 packages with a malicious dependency, easy-day-js, which impersonated the dayjs library. This dependency disabled TLS verification and deployed a cryptocurrency stealer as a payload, exploiting a former contributor's account with unrevoked access. This incident, affecting high-traffic packages like @mastra/core with millions of monthly downloads, exposed credentials and wallets by executing malware at install time on any developer or build machine. The attack mirrors previous npm compromises like the Axios incident, and Mastra's emergency response included removing the malicious code, updating affected packages, and revoking unauthorized access, while emphasizing the importance of maintaining project hygiene and using lockfiles to mitigate such risks.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
LLM 2 6,292 1,205 252 -36%
AI Agents 1 6,200 1,430 272 +10%
Secrets Management 1 2,539 400 136 +9%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.