{"id":754,"date":"2026-06-18T17:18:39","date_gmt":"2026-06-18T11:48:39","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=754"},"modified":"2026-08-18T17:19:45","modified_gmt":"2026-08-18T11:49:45","slug":"mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\/","title":{"rendered":"Mastra npm Supply-Chain Attack Compromises 144 AI Framework Packages"},"content":{"rendered":"<p>The Mastra npm compromise highlights how a single overlooked access permission can ripple through an entire software ecosystem. Security researchers reported that <a href=\"https:\/\/thehackernews.com\/2026\/06\/144-mastra-npm-packages-compromised-via.htmlutm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=mastra_npm_compromise\" target=\"_blank\" rel=\"noopener\">144 npm packages<\/a> associated with the Mastra scope (@mastra\/*) were modified to include a dependency on a malicious third-party package after attackers hijacked a current contributor&#8217;s npm account.<\/p>\n<p>Mastra is an open-source JavaScript and TypeScript framework used to build AI applications. Public reporting indicates the attack relied on trusted package distribution mechanisms rather than a disclosed application vulnerability or user-driven malware download. Instead, attackers abused trust already embedded in the package distribution process.<\/p>\n<p>For organizations building or deploying AI-powered applications, the attack serves as a reminder that software <a href=\"https:\/\/www.hexnode.com\/resources\/reports\/securing-the-supply-chain-sector-a-comprehensive-report\/\">supply-chain security<\/a> extends beyond code reviews and dependency scanning. Access governance can be just as important.<\/p>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/xdr\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tImprove enterprise security using Hexnode<\/a>\r\n    \t\t<\/center><\/p>\n<h2>How a Trusted Contributor Account Became the Entry Point<\/h2>\n<p>Researchers traced the malicious package publications to the npm account of a current Mastra contributor. Public reporting indicates the account retained publishing permissions after the contributor was no longer actively involved with the project.<\/p>\n<h3>According to researchers, the attack was enabled by:<\/h3>\n<ul>\n<li>A current contributor account that still had publishing access.<\/li>\n<li>Unauthorized access to that account.<\/li>\n<li>The ability to publish updates across the Mastra package scope.<\/li>\n<\/ul>\n<p>No vulnerability in Mastra itself has been publicly identified as the initial cause of the incident. Instead, attackers appear to have abused trusted publishing access to distribute malicious package updates.<\/p>\n<p>This incident highlights how unmanaged publishing permissions can become a software supply-chain risk, particularly in projects with multiple contributors and maintainers.<\/p>\n<h2>Why a Single Dependency Reached 144 Packages<\/h2>\n<p>Researchers found that 144 compromised packages within the Mastra scope included a dependency on easy-day-js, a malicious clone of the legitimate Day.js library.<\/p>\n<p>According to SafeDep, easy-day-js was initially published as a clean copy of Day.js before later versions introduced malicious functionality.<\/p>\n<p>Rather than modifying each package individually, the attackers used the dependency to distribute malware across affected package versions. The incident illustrates how a single compromised dependency can extend risk across an entire package ecosystem.<\/p>\n<h2>Inside the easy-day-js Payload Chain<\/h2>\n<p>The malware chain relied on npm&#8217;s package installation process rather than application execution. Researchers reported that easy-day-js contained a malicious post-install script. When an affected package was installed, the script automatically executed without requiring developers to import the library into their projects.<\/p>\n<h3>According to public analyses, the malware:<\/h3>\n<ul>\n<li>Executed an obfuscated JavaScript loader.<\/li>\n<li>Retrieved a second-stage payload from attacker-controlled infrastructure.<\/li>\n<li>Disabled TLS certificate validation.<\/li>\n<li>Launched a detached background process.<\/li>\n<li>Attempted to remove loader artifacts after execution.<\/li>\n<\/ul>\n<h3>Researchers reported that the final payload was capable of:<\/h3>\n<ul>\n<li>Collecting browser history.<\/li>\n<li>Harvesting data from more than 160 cryptocurrency wallet browser extensions.<\/li>\n<li>Installing persistence mechanisms on Windows, macOS, and Linux systems.<\/li>\n<li>Exfiltrating data to command-and-control infrastructure.<\/li>\n<li>Receiving and executing additional attacker commands.<\/li>\n<\/ul>\n<p>The payload was executed during installation, potentially exposing developer environments before the affected package was actively used by an application.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-essentials.jpeg?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Cybersecurity essentials for any organization<\/h4><p>Cybersecurity essentials every organization needs to strengthen security and resilience.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/cybersecurity-essentials-for-any-organization\/\" aria-label=\"Cybersecurity essentials for any organization\"><\/a><\/div><\/div><\/div>\n<h2>Why Developer Environments Face Elevated Risk<\/h2>\n<p>The Mastra compromise affected packages used in AI development workflows, where developer systems may store high-value credentials and operational secrets. Examples include:<\/p>\n<ul>\n<li>Model provider API keys.<\/li>\n<li>Cloud platform credentials.<\/li>\n<li>GitHub and GitLab access tokens.<\/li>\n<li>Package publishing credentials.<\/li>\n<li>Kubernetes secrets.<\/li>\n<li>Deployment automation tokens.<\/li>\n<\/ul>\n<p>The malware was executed during installation, potentially exposing affected systems before developers even used the package. A compromised developer workstation may provide access to build systems, deployment pipelines, cloud environments, and software distribution channels.<\/p>\n<p>As organizations expand AI development initiatives, frameworks that operate within these workflows can expose valuable credentials and operational access if compromised through a supply-chain attack.<\/p>\n<h3>Operational Summary<\/h3>\n<table style=\"width: 68.3657%; height: 216px;\">\n<thead>\n<tr style=\"height: 24px;\">\n<th style=\"width: 35.0937%; height: 24px; text-align: left;\">Category<\/th>\n<th style=\"width: 73.4242%; height: 24px; text-align: left;\">Details<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"height: 24px;\">\n<td style=\"width: 35.0937%; height: 24px;\">Incident Type<\/td>\n<td style=\"width: 73.4242%; height: 24px;\">Software supply-chain attack<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 35.0937%; height: 24px;\">Affected Platform<\/td>\n<td style=\"width: 73.4242%; height: 24px;\">Packages within the Mastra scope (@mastra\/*)<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 35.0937%; height: 24px;\">Packages Impacted<\/td>\n<td style=\"width: 73.4242%; height: 24px;\">144<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 35.0937%; height: 24px;\">Distribution Method<\/td>\n<td style=\"width: 73.4242%; height: 24px;\">Malicious dependency insertion<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 35.0937%; height: 24px;\">Malicious Package<\/td>\n<td style=\"width: 73.4242%; height: 24px;\">easy-day-js<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 35.0937%; height: 24px;\">Execution Method<\/td>\n<td style=\"width: 73.4242%; height: 24px;\">npm postinstall hook<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 35.0937%; height: 24px;\">Primary Risk<\/td>\n<td style=\"width: 73.4242%; height: 24px;\">Endpoint compromise and potential credential theft<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 35.0937%; height: 24px;\">High-Value Exposure Points<\/td>\n<td style=\"width: 73.4242%; height: 24px;\">Developer endpoints and CI\/CD systems<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>What Security Teams Should Verify First<\/h2>\n<p>Although the full impact of the incident remains under investigation, organizations should review systems that may have installed affected package versions.<\/p>\n<h3>Developer Workstations<\/h3>\n<p>Review endpoint telemetry for suspicious Node.js activity, persistence creation, and unusual outbound connections.<\/p>\n<h3>Build Pipelines<\/h3>\n<p>Examine CI\/CD runners and build logs for affected package versions and installation activity.<\/p>\n<h3>Secrets and Tokens<\/h3>\n<p>Consider rotating repository tokens, cloud credentials, API keys, package publishing tokens, and deployment secrets associated with affected systems.<\/p>\n<h3>Package Governance<\/h3>\n<p>Review contributor permissions, publishing controls, and dependency monitoring processes for similar exposure points.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework.png?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity framework\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework.png?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework-300x225.png?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework-768x576.png?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-framework-133x100.png?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity framework\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Building a cybersecurity framework for your enterprise\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Explore cybersecurity frameworks and how UEM strengthens security, visibility, compliance, and organizational resilience.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/white-papers\/building-a-cybersecurity-framework-for-your-enterprise\/'>\n                            DOWNLOAD\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>How Hexnode Supports Investigation and Response<\/h2>\n<p>Incidents like the Mastra compromise often require teams to determine which systems installed affected packages, whether malicious activity occurred after installation, and what devices may need remediation.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/blogs\/xdr-extended-detection-and-response\/\">Hexnode XDR<\/a> unifies endpoint telemetry, automated alert correlation, process analysis, and threat hunting capabilities to support investigation and response for malicious software execution on managed endpoints. Analysts can use the <a href=\"https:\/\/www.hexnode.com\/blogs\/real-time-threat-detection\/\">threat hunting<\/a> query engine of\u00a0 <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-extended-detection-and-response-xdr\/\">XDR<\/a> to search historical process and endpoint event data for indicators of compromise across managed endpoints.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> helps organizations maintain device compliance, enforce configuration policies, manage applications, and perform remote actions across supported Windows, macOS, and Linux endpoints.<\/p>\n<h2>Conclusion<\/h2>\n<p>The Mastra npm compromise demonstrates how a single compromised account can affect an entire package ecosystem when trusted publishing access is abused. The incident also shows how malware delivered through software dependencies can reach developer workstations and build environments before affected code is ever used.<\/p>\n<p>As organizations expand AI development initiatives, maintaining control over contributor access, package publishing permissions, and dependency monitoring remains essential for reducing software supply-chain risk.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Secure development environments with greater visibility <\/h5><p>See how Hexnode helps investigate threats across managed endpoints. <\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> SIGN UP NOW<\/a><\/div><\/div>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What is the Mastra npm compromise?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>The Mastra npm compromise involved attackers publishing malicious versions of 144 packages within the Mastra package scope after hijacking a current contributor&#8217;s npm account.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What is easy-day-js?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>easy-day-js is a malicious npm package that cloned the legitimate Day.js library and was used to deliver malware through compromised Mastra package versions.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Why did the malware execute during installation?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>The malicious dependency used an npm postinstall hook, allowing malware to run during package installation without requiring developers to import or execute the affected package.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>The Mastra npm compromise highlights how a single overlooked access permission can ripple through an&#8230;<\/p>\n","protected":false},"author":5,"featured_media":758,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1,13],"class_list":["post-754","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai-security","category-identity-abuse","product_category-extended-detection-and-response","tab_group-all-threats"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Mastra npm Compromise Impacts 144 AI Framework Packages<\/title>\n<meta name=\"description\" content=\"The Mastra npm compromise exposed 144 packages through a malicious dependency, highlighting software supply-chain risks in AI development.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Mastra npm Compromise Impacts 144 AI Framework Packages\" \/>\n<meta property=\"og:description\" content=\"The Mastra npm compromise exposed 144 packages through a malicious dependency, highlighting software supply-chain risks in AI development.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-18T11:48:39+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-18T11:49:45+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/mastra-npm-compromise.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sophia Hart\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sophia Hart\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\\\/\"},\"author\":{\"name\":\"Sophia Hart\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\"},\"headline\":\"Mastra npm Supply-Chain Attack Compromises 144 AI Framework Packages\",\"datePublished\":\"2026-06-18T11:48:39+00:00\",\"dateModified\":\"2026-08-18T11:49:45+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\\\/\"},\"wordCount\":1076,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/mastra-npm-compromise.jpeg?format=webp\",\"articleSection\":[\"AI Security\",\"Identity Abuse\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\\\/\",\"name\":\"Mastra npm Compromise Impacts 144 AI Framework Packages\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/mastra-npm-compromise.jpeg?format=webp\",\"datePublished\":\"2026-06-18T11:48:39+00:00\",\"dateModified\":\"2026-08-18T11:49:45+00:00\",\"description\":\"The Mastra npm compromise exposed 144 packages through a malicious dependency, highlighting software supply-chain risks in AI development.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/mastra-npm-compromise.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/mastra-npm-compromise.jpeg?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"mastra npm compromise\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Mastra npm Supply-Chain Attack Compromises 144 AI Framework Packages\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\",\"name\":\"Sophia Hart\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"caption\":\"Sophia Hart\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/sophia-hart\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Mastra npm Compromise Impacts 144 AI Framework Packages","description":"The Mastra npm compromise exposed 144 packages through a malicious dependency, highlighting software supply-chain risks in AI development.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\/","og_locale":"en_US","og_type":"article","og_title":"Mastra npm Compromise Impacts 144 AI Framework Packages","og_description":"The Mastra npm compromise exposed 144 packages through a malicious dependency, highlighting software supply-chain risks in AI development.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-06-18T11:48:39+00:00","article_modified_time":"2026-08-18T11:49:45+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/mastra-npm-compromise.jpeg?format=webp","type":"image\/jpeg"}],"author":"Sophia Hart","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Sophia Hart","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\/"},"author":{"name":"Sophia Hart","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430"},"headline":"Mastra npm Supply-Chain Attack Compromises 144 AI Framework Packages","datePublished":"2026-06-18T11:48:39+00:00","dateModified":"2026-08-18T11:49:45+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\/"},"wordCount":1076,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/mastra-npm-compromise.jpeg?format=webp","articleSection":["AI Security","Identity Abuse"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\/","url":"https:\/\/www.hexnode.com\/threat-watch\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\/","name":"Mastra npm Compromise Impacts 144 AI Framework Packages","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/mastra-npm-compromise.jpeg?format=webp","datePublished":"2026-06-18T11:48:39+00:00","dateModified":"2026-08-18T11:49:45+00:00","description":"The Mastra npm compromise exposed 144 packages through a malicious dependency, highlighting software supply-chain risks in AI development.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/mastra-npm-compromise.jpeg?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/mastra-npm-compromise.jpeg?format=webp","width":1340,"height":700,"caption":"mastra npm compromise"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/mastra-npm-supply-chain-attack-compromises-144-ai-framework-packages\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Mastra npm Supply-Chain Attack Compromises 144 AI Framework Packages"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430","name":"Sophia Hart","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","caption":"Sophia Hart"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/sophia-hart\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/754","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=754"}],"version-history":[{"count":2,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/754\/revisions"}],"predecessor-version":[{"id":762,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/754\/revisions\/762"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/758"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=754"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=754"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}