Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

An unknown attacker hijacked the npm maintainer account for the Mastra AI framework and published poisoned versions of 140+ packages that silently install a remote access trojan and credential-stealing malware during routine dependency installation. Any developer workstation or CI/CD pipeline that ran npm install or npm update against @mastra packages after June 17, 2026 at 01:01 UTC must be treated as fully compromised. The business risk spans source code theft, credential exfiltration, cryptocurrency wallet drain, and lateral movement from developer environments into production systems.

Author

Tech Jacks Solutions