AIO APEX

News

Breaking news and updates from the world of technology.

144 Mastra npm Packages Backdoored in 88-Minute Supply Chain Attack
Security

144 Mastra npm Packages Backdoored in 88-Minute Supply Chain Attack

An attacker hijacked a contributor account with publishing rights to the Mastra AI framework's npm organization and republished 144 packages with a typosquatted dependency that deployed a cross-platform infostealer. Any system that ran npm install with a @mastra/* package after June 16 is potentially compromised.

Socket
supply-chain-attackmalware
15 malicious JetBrains plugins spent 8 months stealing developers' AI API keys
Security

15 malicious JetBrains plugins spent 8 months stealing developers' AI API keys

Attackers published 15 fake AI coding plugins on the JetBrains Marketplace under seven vendor accounts, collectively downloaded nearly 70,000 times. Each plugin silently exfiltrated OpenAI, DeepSeek, and SiliconFlow API keys to an attacker-controlled server.

BleepingComputer
api-keyssupply-chain-attack