144 Mastra npm Packages Compromised via Hijacked Contributor Account

As many as 144 npm packages associated with the Mastra namespace (“@mastra/*”), a popular open-source JavaScript and TypeScript framework for building artificial intelligence (AI) applications, have been compromised as part of a software supply chain attack codenamed easy-day-js, per findings from JFrog, SafeDep, Socket, and StepSecurity.

“A single npm account (ehindero) mass-published more

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

India’s first privately-developed rocket reaches orbit on dramatic debut launch

India’s first privately-developed rocket reaches orbit on dramatic debut launch Source: Hacker News

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six

The AI Aesthetic

The AI Aesthetic Source: Hacker News