Product
Mastra
- First Reported
- Jun 17, 2026
- Latest Reported
- Jun 17, 2026
Reported Context (1)
- Socket has detected a malicious npm supply chain campaign involving compromised @mastra/* packages published under the Mastra namespace. A single npm account (ehindero) mass-published more than 140 malicious packages Malicious Dependency Compromises 141 Mastra npm Packages in Supply-Chain Campaign
Malware (1)
MITRE ATT&CK (17)
Vendors (1)
Products (14)
Tools (1)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.