144 Mastra npm packages compromised in major software supply chain attack
In June 2026, attackers hijacked the npm contributor account 'ehindero' to mass-publish malicious versions of 144 packages under the @mastra namespace, in what security researchers from JFrog, SafeDep, Socket, and StepSe…