From package to postinstall payload: Inside the Mastra npm supply chain compromise

Reported 18 Jun 2026 by otx · Severity: medium

Microsoft Threat Intelligence discovered a large-scale npm supply chain attack compromising over 140 packages in the mastra and @mastra scopes. The attack originated from takeover of the ehindero npm maintainer account, which published poisoned package versions introducing easy-d