
144 Mastra npm Packages Backdoored in 88-Minute Supply Chain Attack
An attacker hijacked a contributor account with publishing rights to the Mastra AI framework's npm organization and republished 144 packages with a typosquatted dependency that deployed a cross-platform infostealer. Any system that ran npm install with a @mastra/* package after June 16 is potentially compromised.










