The Mastra npm Supply Chain Attack
Updated 5 Oct 2026 · Incident date 17 Jun 2026 · npm
@mastra/* - 141+ packages republished with poisoned versions via the hijacked maintainer account 'ehindero'package.jsonOn 17 June 2026 an attacker used a hijacked maintainer account to publish poisoned versions of more than 140 Mastra npm packages, including mastra 1.13.1 and @mastra/core 1.42.1. Each poisoned release gained one new dependency named easy-day-js, a look-alike of the dayjs date library.
The easy-day-js dependency runs an install hook that downloads a stealer and remote-access tool. Microsoft links the attack to the North Korean group Sapphire Sleet.
What happened
An attacker published a fake dependency, then used a maintainer's npm account to add it to 140 or more @mastra packages. Source reports give counts from 80 to 145, because the count grew as researchers found more packages.
The timeline in UTC, from the sources:
- 16 June 2026, 07:05: easy-day-js 1.11.21 appears. It is clean and works as bait. The publisher is the account
sergey2016. - 17 June 2026, 01:01: easy-day-js 1.11.22 appears with a malicious install hook.
- 17 June 2026, from about 01:20: the poisoned @mastra packages go out through the account
ehindero. The Hacker News reports that the publishes took 88 minutes.
Each poisoned package lists easy-day-js with the range ^1.11.21. That range resolves to 1.11.22. The package.json of the Mastra package shows the new dependency, but the Mastra code itself is not the carrier.
Every @mastra package had clean releases before this. That is why a version comparison finds the change. The new dependency carries an install hook that did not exist before.
The Hacker News reports the root cause as a social engineering attack on a Mastra maintainer through LinkedIn. It also reports that token settings allowed publishing without multi-factor authentication. Microsoft assesses with high confidence that Sapphire Sleet is behind the attack. BleepingComputer reports that the same group is linked to the April 2026 Axios compromise. See the Axios attack page.
What the payload does, as Microsoft describes it:
- The install hook runs
node setup.cjs --no-warnings. The dropper is 4,572 bytes and uses obfuscated strings. - The dropper turns off TLS certificate checks. It writes marker files in the temp directory, named
.pkg_historyand.pkg_logs. - It contacts
23.254.164.92and downloads a second-stage implant of about 41 KB. It runs the implant as a hidden, detached Node.js process. - The implant collects host data, browser history and installed applications. It checks for 166 crypto wallet browser extension IDs, including MetaMask, Phantom, Coinbase Wallet, Binance Wallet and TronLink.
- The implant adds a login persistence entry on Windows, macOS and Linux. Each entry mimics Node version manager names.
- On Windows, a later PowerShell backdoor adds a Defender exclusion for
C:\Windows\System32and installs a service namedscdevthat runs as SYSTEM.
Affected versions
The sources name these versions as poisoned. The full list of 140 or more packages is in the Microsoft and Hacker News reports.
- mastra 1.13.1 (published 17 June 2026). Version 1.13.0 and earlier are not affected.
- @mastra/core 1.42.1. Version 1.42.0 and earlier are not affected.
- create-mastra 1.13.1
- easy-day-js 1.11.22, the malicious dependency. Version 1.11.21 is the clean bait release.
@mastra/core had about 918,000 weekly downloads at the time, according to BleepingComputer.
Any @mastra package that lists easy-day-js in its dependencies is poisoned. Use that test, not a version list, for packages that this page does not name.
Indicators of compromise
- Dependency name:
easy-day-js(version 1.11.22, range^1.11.21) - npm accounts:
ehindero(hijacked maintainer),sergey2016(easy-day-js publisher) - Install command:
node setup.cjs --no-warnings - Dropper SHA-256 (setup.cjs):
B122A9873BEDF145AE2A7FD024B5F309007DBB025149F4DC4AC3F7E4F32A36A4 - easy-day-js-1.11.22.tgz SHA-256:
AE70DD4F6BC0D1C8C2848E4E6B51934626C4818DCB5AF99D080DDBD7DC337185 - mastra-1.13.1.tgz SHA-256:
B73DE25C053C3225A077738A1FCBD9CA6966D7B3CD6F5494A30F0AA0EAE55C7E - C2 IP addresses:
23.254.164.92and23.254.164.123 - Payload URL:
https://23.254.164.92:8000/update/49890878 - Domains:
teams.onweblive.organdmaskasd.com - Marker files:
$TMPDIR/.pkg_historyand$TMPDIR/.pkg_logs - Persistence: Windows Run key value
NvmProtocal, macOScom.nvm.protocal.plistin~/Library/NodePackages/, Linuxnvmconf.servicein~/.config/systemd/nvmconf/ - Implant file name:
protocal.cjs(spelled this way) - Windows service:
scdevwith DLL pathC:\windows\system32\scdev.dll
How to check
Search your lockfiles and installed modules for easy-day-js. Any hit means a poisoned package resolved on that machine.
npm ls easy-day-js
grep -n "easy-day-js" package-lock.json
Then check the installed Mastra versions.
npm ls mastra @mastra/core create-mastra
Check for the marker files from the dropper.
ls -la "${TMPDIR:-/tmp}"/.pkg_history "${TMPDIR:-/tmp}"/.pkg_logsCheck CI logs and firewall logs for connections to 23.254.164.92 and 23.254.164.123.
Vigilance compares the release you trust with the new one and reports the file that gained a new capability. For this attack, the changed file is package.json. It gained a dependency that carries an install hook, downloads a payload and runs it.
What to do now
- Pin mastra to 1.13.0 or earlier and @mastra/core to 1.42.0 or earlier until you confirm a clean release.
- Remove
node_modulesand reinstall from a clean lockfile. Usenpm install --ignore-scriptsto stop install hooks while you investigate. - Treat any workstation, CI runner or build agent that resolved easy-day-js as compromised.
- Rotate credentials, tokens and API keys that were present on those machines.
- Move crypto assets from any wallet that had a browser extension on an affected machine.
- Block
23.254.164.92,23.254.164.123,teams.onweblive.organdmaskasd.comat the network edge. - On Windows, check for the
scdevservice and the Defender exclusion forC:\Windows\System32. Rebuild the machine if you find them. - Audit CI logs for install-time outbound connections.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 30 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED package.json It now runs a command on its own when it is installed, downloads from the internet and reads saved passwords and access keys. It did not before.
Frequently asked questions
Which Mastra npm packages were compromised?
More than 140 packages in the mastra and @mastra scopes, including mastra 1.13.1, @mastra/core 1.42.1 and create-mastra 1.13.1. Every poisoned package lists the malicious dependency easy-day-js 1.11.22.
What is easy-day-js?
easy-day-js is a typosquat of the dayjs date library. Version 1.11.22 has an install hook that runs setup.cjs. The script downloads a second-stage stealer and remote-access tool from attacker servers.
Who is behind the Mastra npm attack?
Microsoft attributes the attack to Sapphire Sleet, a North Korean state-sponsored group, with high confidence. The group is also tracked as BlueNoroff. It targets crypto wallets.
Sources
More supply chain attacks
- @apexacc/cli Defender-blinding C2 loader 17 Sept 2026
- keyv / cacheable npm worm (Shai-Hulud third wave) 4 Aug 2026
- TanStack npm compromise (Mini Shai-Hulud) 11 May 2026
- axios npm maintainer account takeover 31 Mar 2026
All 111 attacks in the library · npm supply chain attacks · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.