Utopia Tech
SecurityAI-assisted1 min read

144 Mastra npm Packages Compromised via Hijacked Contributor Account

A software supply chain attack codenamed 'easy-day-js' compromised 144 npm packages within the Mastra namespace, a popular framework for building AI applications. The attack was executed through a hijacked contributor account (ehindero) that mass-published malicious packages, posing significant risks to organizations using this JavaScript/TypeScript framework.

UT

Utopia Tech

June 17, 2026 · 1 min read

Share

As many as 144 npm packages associated with the Mastra namespace ("@mastra/*"), a popular open-source JavaScript and TypeScript framework for building artificial intelligence (AI) applications, have been compromised as part of a software supply chain attack codenamed easy-day-js, per findings from JFrog, SafeDep, Socket, and StepSecurity. "A single npm account (ehindero) mass-published more

Originally published at thehackernews.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content