140+ Mastra npm Packages Compromised in Coordinated Supply Chain Attack
Blog post from Socket
Socket has uncovered a significant npm supply chain attack involving over 140 compromised packages published within the @mastra namespace. These packages, published by a single npm account, contained an injected typosquatted dependency, easy-day-js, which harbored malware. This malware executed automatically during npm installation, potentially compromising systems before developers used the packages. The attack involved a two-stage payload; the first stage deactivated TLS verification, fetched a second-stage payload, and executed it as a background process. The second stage acted as a cross-platform infostealer targeting browser histories and cryptocurrency wallet data, establishing persistence on Windows, macOS, and Linux. Despite the malicious nature of these packages, Socket's proactive measures ensured that installations of affected packages were quickly flagged and blocked, limiting potential damage. The incident underscores the importance of vigilant monitoring and control over dependency installations to safeguard against similar supply chain threats.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| MCP | 3 | 7,668 | 844 | 209 | +8% |
| OpenTelemetry | 2 | 968 | 178 | 57 | +2% |
| Real-time | 2 | 5,758 | 1,361 | 266 | +0% |
| Secrets Management | 2 | 2,515 | 393 | 134 | +17% |
| Observability | 1 | 4,230 | 776 | 198 | +24% |
| RAG | 1 | 1,000 | 260 | 106 | -52% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.