Over 140 popular Mastra npm Packages Hit by Supply Chain Attack
aikido.dev | incident | #ai-security | #supply-chain | #open-source | #malware | #npm | #aikido | #ai-agents | #supply-chain-attack | #mastra | #crypto-theft | #postinstall | #wallet-theft | #crypto-wallets | #crypto-wallet-theft | #crypto-wallet-stealer | #dayjs
Summary
Aikido detected an attack republishing 141 @mastra npm packages with a malicious dayjs clone, easy-day-js, whose postinstall hook deploys a payload targeting 160+ browser crypto wallets.
- Published
- Collected
Skip to content