ended6월 17일· 1 sources
144 Mastra Packages Weaponized in npm's Largest Targeted Supply Chain Attack
npm 최대 규모 공급망 공격, Mastra 144개 패키지 동시 장악
Why it matters
The compromise of 144 Mastra npm packages represents one of the JavaScript ecosystem's largest targeted supply chain attacks, directly threatening AI application development infrastructure. Exploiting a single hijacked npm account, attackers distributed malicious code at scale while bypassing normal review mechanisms, exposing a fundamental vulnerability in open-source's trust model. Developers must immediately audit Mastra dependencies and implement verification mechanisms to prevent similar mass-poisoning incidents.
1
Sources
+0
24h
—
Growth
95d
Active
npm packagessupply chainMastraaccount hijackingmalicious code