This page summarizes the Mastra Supply Chain Compromise affecting multiple npm packages in the @mastra npm ecosystem.

The compromise involved packages under the @mastra npm scope being republished with an injected malicious dependency, easy-day-js. The malicious dependency executes during package installation through a postinstall hook and acts as a dropper for a second-stage payload.

The compromised packages reportedly included mechanisms for credential and cryptocurrency wallet theft, host and environment data collection, persistence, and communication with attacker-controlled infrastructure.

You can use this page to identify affected package versions and review recommended remediation actions.

For additional background and technical details, please refer to the Snyk Blog post

Packages affected by zero-day vulnerabilities

Showing 30 of 144 • Page 1 of 5

Page 1 of 5