Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

On June 17, 2026, attackers hijacked a dormant contributor account for the Mastra AI development framework and published malicious versions of 144 npm packages within 88 minutes, injecting credential and cryptocurrency-stealing malware into a supply chain used by AI and cloud development teams. Any workstation, CI/CD pipeline, or build runner that installed affected @mastra/* package versions during the compromise window must be treated as fully compromised, including all stored credentials, API keys, and cryptocurrency wallet data. With over 918,000 weekly downloads of @mastra/core alone, the blast radius spans development organizations globally, with direct exposure to source code repositories, cloud provider credentials, and internal infrastructure accessible from poisoned build environments.

Author

Tech Jacks Solutions