Lotu Radar About · RSS

A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope

Snyk Blog Cybersecurity Score 6/10

Summary

A dormant contributor account was used to republish the entire @mastra npm scope, each injected with a single dependency, easy-day-js, that drops a cross-platform cryptocurrency stealer. Here is how the attack worked, how to check exposure, and how to remediate.

Developer ToolsSecurity

Lotu Radar provides attributed news summaries and links to the original publisher. Full reporting and copyright remain with the source.