Sunday 26 July 2026 23:44:51 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

#Mastra


Mastra’s npm Trail Turns a Package Update Into a Crypto-Extension Risk

Published: 22 June 2026 14:14Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

A malicious dependency found in more than 140 Mastra packages shows how a software supply-chain incident can move from build tools to browser-facing cryptocurrency surfaces.

One Hijacked npm Identity Can Poison an Entire Dependency Chain

Published: 22 June 2026 10:28Category: CybercrimeGeo: North America / USAAuthor: CIPHERWARDEN

A maintainer-account takeover tied to poisoned Mastra packages shows how package registries can become malware delivery systems when publisher trust is broken.

When a Trusted Package Turns Toxic: The Mastra npm Intrusion

Published: 22 June 2026 10:12Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

A hijacked maintainer path, a typosquat package, and two very different payloads show how supply-chain abuse can reach far beyond one namespace.

When a Package Registry Turns into a Blind Spot for AI Builders

Published: 20 June 2026 18:48Category: Cyber Warfare & Nation-State OperationsGeo: North America / USAAuthor: AGONY

Microsoft’s attribution of a Mastra AI-related npm compromise to Sapphire Sleet shows how a software supply chain incident can ripple through developer tooling long before anyone notices a malicious build.

When Trusted Packages Turn Toxic: The Mastra npm Incident and the New Face of Credential Theft

Published: 17 June 2026 17:38Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

More than 140 npm packages tied to the Mastra AI ecosystem were reported compromised, underscoring how a single poisoned dependency can become a delivery path for infostealers.

Namespace Trust Broke First: The npm Supply Chain Story Hidden Inside Mastra

Published: 17 June 2026 17:17Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

More than 140 packages in the Mastra namespace were reported as part of a supply-chain compromise, with a typosquatting dependency, easy-day-js, used in a way that could fit install-time malware delivery.

A Trusted npm Namespace Became the Weak Link in an AI Build Chain

Published: 17 June 2026 10:13Category: CybercrimeGeo: North America / USAAuthor: CIPHERWARDEN

A hijacked contributor identity and a burst of package publishing turned the @mastra/* ecosystem into a supply-chain warning for anyone shipping JavaScript or TypeScript at scale.