Home / Companies / Socket / Blog / Post Details
Content Deep Dive

140+ Mastra npm Packages Compromised in Coordinated Supply Chain Attack

Blog post from Socket

Post Details
Company
Date Published
Author
Socket Research Team
Word Count
2,970
Company Posts That Month
27
Language
English
Hacker News Points
-
Post removed?
No
Summary

Socket has uncovered a significant npm supply chain attack involving over 140 compromised packages published within the @mastra namespace. These packages, published by a single npm account, contained an injected typosquatted dependency, easy-day-js, which harbored malware. This malware executed automatically during npm installation, potentially compromising systems before developers used the packages. The attack involved a two-stage payload; the first stage deactivated TLS verification, fetched a second-stage payload, and executed it as a background process. The second stage acted as a cross-platform infostealer targeting browser histories and cryptocurrency wallet data, establishing persistence on Windows, macOS, and Linux. Despite the malicious nature of these packages, Socket's proactive measures ensured that installations of affected packages were quickly flagged and blocked, limiting potential damage. The incident underscores the importance of vigilant monitoring and control over dependency installations to safeguard against similar supply chain threats.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
MCP 3 7,668 844 209 +8%
OpenTelemetry 2 968 178 57 +2%
Real-time 2 5,758 1,361 266 +0%
Secrets Management 2 2,515 393 134 +17%
Observability 1 4,230 776 198 +24%
RAG 1 1,000 260 106 -52%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.