ended6월 17일· 1 sources

144 Mastra Packages Weaponized in npm's Largest Targeted Supply Chain Attack

npm 최대 규모 공급망 공격, Mastra 144개 패키지 동시 장악

Why it matters

The compromise of 144 Mastra npm packages represents one of the JavaScript ecosystem's largest targeted supply chain attacks, directly threatening AI application development infrastructure. Exploiting a single hijacked npm account, attackers distributed malicious code at scale while bypassing normal review mechanisms, exposing a fundamental vulnerability in open-source's trust model. Developers must immediately audit Mastra dependencies and implement verification mechanisms to prevent similar mass-poisoning incidents.

1
Sources
+0
24h
Growth
95d
Active
npm packagessupply chainMastraaccount hijackingmalicious code

Sources

Related Issues