A malicious dependency found in more than 140 Mastra packages shows how a software supply-chain incident can move from build tools to browser-facing cryptocurrency surfaces.
A maintainer-account takeover tied to poisoned Mastra packages shows how package registries can become malware delivery systems when publisher trust is broken.
A hijacked maintainer path, a typosquat package, and two very different payloads show how supply-chain abuse can reach far beyond one namespace.
Microsoft’s attribution of a Mastra AI-related npm compromise to Sapphire Sleet shows how a software supply chain incident can ripple through developer tooling long before anyone notices a malicious build.
More than 140 npm packages tied to the Mastra AI ecosystem were reported compromised, underscoring how a single poisoned dependency can become a delivery path for infostealers.
More than 140 packages in the Mastra namespace were reported as part of a supply-chain compromise, with a typosquatting dependency, easy-day-js, used in a way that could fit install-time malware delivery.
A hijacked contributor identity and a burst of package publishing turned the @mastra/* ecosystem into a supply-chain warning for anyone shipping JavaScript or TypeScript at scale.