144 Mastra npm Packages Compromised via Hijacked Contributor Account

As many as 144 npm packages associated with the Mastra namespace (“@mastra/*”), a popular open-source JavaScript and TypeScript framework for building artificial intelligence (AI) applications, have been compromised as part of a software supply chain attack codenamed easy-day-js, per findings from JFrog, SafeDep, Socket, and StepSecurity.

“A single npm account (ehindero) mass-published more

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

OverpAId – Fire your CEO. Hire the future

OverpAId – Fire your CEO. Hire the future Source: Hacker News

URGENT – Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat

URGENT – Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat Progress Software has told ShareFile customers to shut down the Windows servers running their Storage

Migrating a production AI agent to GPT-5.6: 2.2x faster, 27% cheaper

Migrating a production AI agent to GPT-5.6: 2.2x faster, 27% cheaper Source: Hacker News