Loading...
[Over 140 Mastra npm Packages Hit by Supply Chain Attack] SlowMist reports that over 140 Mastra-related npm packages have been targeted in a supply chain attack. The affected versions introduced the malicious dependency easy-day-js@1.11.22, which triggers code execution during the installation phase. SlowMist recommends treating systems that have installed the affected versions as compromised, immediately removing the malicious dependency, reinstalling trusted versions, isolating the host, and rotating credentials.