The Mastra npm Supply Chain Attack

Updated 5 Oct 2026 · Incident date 17 Jun 2026 · npm

Package@mastra/* - 141+ packages republished with poisoned versions via the hijacked maintainer account 'ehindero'
Filepackage.json

On 17 June 2026 an attacker used a hijacked maintainer account to publish poisoned versions of more than 140 Mastra npm packages, including mastra 1.13.1 and @mastra/core 1.42.1. Each poisoned release gained one new dependency named easy-day-js, a look-alike of the dayjs date library.

The easy-day-js dependency runs an install hook that downloads a stealer and remote-access tool. Microsoft links the attack to the North Korean group Sapphire Sleet.

What happened

An attacker published a fake dependency, then used a maintainer's npm account to add it to 140 or more @mastra packages. Source reports give counts from 80 to 145, because the count grew as researchers found more packages.

The timeline in UTC, from the sources:

Each poisoned package lists easy-day-js with the range ^1.11.21. That range resolves to 1.11.22. The package.json of the Mastra package shows the new dependency, but the Mastra code itself is not the carrier.

Every @mastra package had clean releases before this. That is why a version comparison finds the change. The new dependency carries an install hook that did not exist before.

The Hacker News reports the root cause as a social engineering attack on a Mastra maintainer through LinkedIn. It also reports that token settings allowed publishing without multi-factor authentication. Microsoft assesses with high confidence that Sapphire Sleet is behind the attack. BleepingComputer reports that the same group is linked to the April 2026 Axios compromise. See the Axios attack page.

What the payload does, as Microsoft describes it:

  1. The install hook runs node setup.cjs --no-warnings. The dropper is 4,572 bytes and uses obfuscated strings.
  2. The dropper turns off TLS certificate checks. It writes marker files in the temp directory, named .pkg_history and .pkg_logs.
  3. It contacts 23.254.164.92 and downloads a second-stage implant of about 41 KB. It runs the implant as a hidden, detached Node.js process.
  4. The implant collects host data, browser history and installed applications. It checks for 166 crypto wallet browser extension IDs, including MetaMask, Phantom, Coinbase Wallet, Binance Wallet and TronLink.
  5. The implant adds a login persistence entry on Windows, macOS and Linux. Each entry mimics Node version manager names.
  6. On Windows, a later PowerShell backdoor adds a Defender exclusion for C:\Windows\System32 and installs a service named scdev that runs as SYSTEM.

Affected versions

The sources name these versions as poisoned. The full list of 140 or more packages is in the Microsoft and Hacker News reports.

@mastra/core had about 918,000 weekly downloads at the time, according to BleepingComputer.

Any @mastra package that lists easy-day-js in its dependencies is poisoned. Use that test, not a version list, for packages that this page does not name.

Indicators of compromise

How to check

Search your lockfiles and installed modules for easy-day-js. Any hit means a poisoned package resolved on that machine.

npm ls easy-day-js
grep -n "easy-day-js" package-lock.json

Then check the installed Mastra versions.

npm ls mastra @mastra/core create-mastra

Check for the marker files from the dropper.

ls -la "${TMPDIR:-/tmp}"/.pkg_history "${TMPDIR:-/tmp}"/.pkg_logs

Check CI logs and firewall logs for connections to 23.254.164.92 and 23.254.164.123.

Vigilance compares the release you trust with the new one and reports the file that gained a new capability. For this attack, the changed file is package.json. It gained a dependency that carries an install hook, downloads a payload and runs it.

What to do now

  1. Pin mastra to 1.13.0 or earlier and @mastra/core to 1.42.0 or earlier until you confirm a clean release.
  2. Remove node_modules and reinstall from a clean lockfile. Use npm install --ignore-scripts to stop install hooks while you investigate.
  3. Treat any workstation, CI runner or build agent that resolved easy-day-js as compromised.
  4. Rotate credentials, tokens and API keys that were present on those machines.
  5. Move crypto assets from any wallet that had a browser extension on an affected machine.
  6. Block 23.254.164.92, 23.254.164.123, teams.onweblive.org and maskasd.com at the network edge.
  7. On Windows, check for the scdev service and the Defender exclusion for C:\Windows\System32. Rebuild the machine if you find them.
  8. Audit CI logs for install-time outbound connections.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old @mastra/-prev --new @mastra/-current
files scanned: 30

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    package.json
           It now runs a command on its own when it is installed, downloads from the internet and reads saved passwords and access keys. It did not before.

Frequently asked questions

Which Mastra npm packages were compromised?

More than 140 packages in the mastra and @mastra scopes, including mastra 1.13.1, @mastra/core 1.42.1 and create-mastra 1.13.1. Every poisoned package lists the malicious dependency easy-day-js 1.11.22.

What is easy-day-js?

easy-day-js is a typosquat of the dayjs date library. Version 1.11.22 has an install hook that runs setup.cjs. The script downloads a second-stage stealer and remote-access tool from attacker servers.

Who is behind the Mastra npm attack?

Microsoft attributes the attack to Sapphire Sleet, a North Korean state-sponsored group, with high confidence. The group is also tracked as BlueNoroff. It targets crypto wallets.

Sources

  1. microsoft.com/en-us/security/blog/2026/06/17/postinstall-payload-inside-mastra-npm-supply-chain-compromise/
  2. thehackernews.com/2026/06/144-mastra-npm-packages-compromised-via.html
  3. bleepingcomputer.com/news/security/microsoft-links-mastra-ai-supply-chain-attack-to-north-korean-hackers/

More supply chain attacks

All 111 attacks in the library · npm supply chain attacks · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free