Skip to content

the entire @mastra npm scope got hijacked last night with 141 packages including @mastra/core

Reddit /u/BattleRemote3157 June 17, 2026

The attacker didn't touch any Mastra source code but just added one dependency to every package: easy-day-js which is a clean-looking dayjs clone. The trick was in semver that is they pinned ^1.11.21 but the latest tag pointed to 1.11.22 which had a postinstall hook. You audit 1.11.21 but npm installs 1.11.22 . full details - submitted by /u/BattleRemote3157 [link] [ ]

Extracted Entities

Attack Types (1)

Companies (1)

Tools (1)