Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

On June 17, 2026, attackers hijacked a dormant Mastra contributor npm account and published malicious versions of 144 @mastra/* packages within 88 minutes, injecting a cross-platform credential and cryptocurrency-stealing payload via the ‘easy-day-js’ dependency. Any development environment, CI/CD pipeline, or build runner that installed affected @mastra/* versions during the compromise window must be treated as fully compromised, with all stored credentials, API keys, and cloud access requiring immediate rotation.

Author

Tech Jacks Solutions