Mastra — Cyber Attacks, Breaches & Threat Activity

Threat entity extracted from intelligence sources

Frequency
7
occurrences
First Seen
June 17, 2026
Last Seen
June 22, 2026

Mastra is a organization tracked across 1 threat cluster and 7 intelligence report mentions on ThreatCluster. First observed June 17, 2026; most recent activity June 22, 2026.

Related Threat Clusters

  • Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages

    A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…

    690 articles · Updated April 29, 2026

Recent Intelligence Reports

  • North Korean Hackers Abuse Mastra npm Supply Chain to Target Developers and CI/CD Pipelines — Cybersecuritynews · June 22, 2026
  • easy-day — Sonatype · June 17, 2026
  • Mastra npm packages compromised in 'easy-day-js' supply chain attack — Feeds.Feedburner · June 17, 2026
  • A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope — Snyk · June 17, 2026
  • A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope — Snyk · June 17, 2026
  • Mastra npm Org Compromised: Multiple Packages Trojanized to Drop a Remote Payload via ... — Endorlabs · June 17, 2026
  • the entire @mastra npm scope got hijacked last night with 141 packages including @mastra/core — Reddit · June 17, 2026

CVSS v3.1 Breakdown