Mastra AI Framework Hit by Supply Chain Attack Compromising Over 140 npm Packages
A sophisticated supply chain attack targeting the popular Mastra artificial intelligence development framework was identified on June 17, 2026, compromising more than 140 software packages in the npm registry. According to reports from Microsoft Threat Intelligence, the attacker gained control of a maintainer's account to inject a malicious dependency into the ecosystem, creating a significant security risk for developers and organizations using the framework.
The incident began with the takeover of the 'ehindero' npm maintainer account, which possessed publishing rights for packages within the Mastra project. Using this access, the attacker systematically updated at least 13 core Mastra packages, adding a new, malicious dependency named 'easy-day-js'. This package was a typosquat, intentionally named to mimic the widely used and legitimate 'dayjs' date-handling library.
The attack was executed in two phases to evade initial detection. On June 16, 2026, the attacker first published a seemingly benign version of 'easy-day-js', which contained only legitimate code copied from the 'dayjs' library. This initial version, tagged 1.11.21, served as bait. The following day, at 1:01 AM UTC on June 17, a weaponized version, 1.11.22, was published. This new version included an obfuscated payload and a 'postinstall' script designed to execute malicious code automatically on a developer's machine as soon as the package was installed.
Starting just 11 minutes after the malicious package went live, the attacker began republishing the compromised Mastra packages. They were modified to list '"easy-day-js": "^1.11.21"' as a dependency. Due to the way npm's semantic versioning works, this specification would automatically resolve to and install the latest compatible version, which was the malicious 1.11.22, thereby infecting any system performing a fresh installation or update.
The payload's behavior, analyzed by Microsoft and other security firms like StepSecurity and Kodem, revealed a multi-step process aimed at stealth and persistence. The 'postinstall' hook triggered a script named 'setup.cjs'. This script first disabled TLS certificate validation, allowing it to communicate with attacker-controlled servers without security warnings. It then downloaded a second-stage payload from a remote server.
This secondary payload was executed as a hidden, detached process to avoid drawing attention. The script also created tracking files in the user's home directory to prevent re-infection of the same machine. In a final step to cover its tracks, the initial 'setup.cjs' dropper script deleted itself from the file system, removing forensic evidence of the initial compromise.
Security researchers believe the primary objective of the attack was to harvest sensitive credentials from developer environments and continuous integration/continuous delivery (CI/CD) pipelines. Given that Mastra is a framework for building AI agents, the stolen credentials could include high-value targets such as LLM API keys, cloud provider secrets, and source code repository tokens. The potential impact is substantial, as some of the compromised core packages, like '@mastra/core', receive nearly a million weekly downloads, indicating a wide blast radius.
In response to the discovery, Microsoft Threat Intelligence notified the npm security team. The malicious packages, including all versions of 'easy-day-js' and the compromised Mastra packages, were promptly removed from the public registry. The attacker’s publishing access to the '@mastra' scope was also revoked.
This incident is a stark reminder that software supply chains remain a critical vulnerability for businesses of all sizes. In our experience, small and mid-sized companies are often the most exposed, as they may rely heavily on open-source software without having dedicated security teams to vet every dependency. The operational disruption and financial damage from a compromised software package can be devastating, leading to stolen intellectual property, exposed customer data, and significant reputational harm. This is not merely an IT issue; it is a core business threat that demands board-level attention. Proactive financial risk management must now fully encompass the technological landscape, including the integrity of the software that powers daily operations. C&S Finance Group LLC helps clients develop robust frameworks to identify and mitigate these exact kinds of operational threats; business owners can learn more at csfinancegroup.com.
The Mastra attack underscores a growing trend of targeting popular development ecosystems to achieve widespread compromise. As a result of this and similar incidents, the npm registry has announced plans to disable 'postinstall' scripts by default in a future major version release. In the meantime, developers using the Mastra framework are urged to audit their dependencies, check for indicators of compromise, and ensure they are using clean, verified versions of all packages.