03:24
2026-06-17
endorlabs.com
ai-safety
Mastra compromised in supply chain attack
An attacker hijacked a Mastra maintainer's account and republished 116 packages in the @mastra catalog over 27 minutes, adding a hidden dependency on the typosquat package easy-day-js. The malicious pโฆ