On 17 June 2026, an attacker used the npm account of a former Mastra contributor to republish more than 140 packages of Mastra, an open source TypeScript framework for building AI agents, with a malicious dependency added. The dependency, easy-day-js, was a lookalike of the popular dayjs library whose postinstall script downloaded a remote access trojan and cryptocurrency stealer onto any developer machine or CI runner that installed it. The account, ehindero, still held publishing rights across the Mastra npm scope long after its owner stopped contributing, and Mastra's co-founder said "a token associated with their account" published the malicious versions. Microsoft Threat Intelligence attributes the campaign with high confidence to Sapphire Sleet, a North Korean state actor. Mastra said the same day that the malicious versions had been unpublished or deprecated, and it has since moved to MFA-only publishing. The incident is a clear case of an unrevoked publishing identity turning into a distribution channel for malware.
Key takeaways
- The malicious [email protected] was published at 01:01 UTC on 17 June 2026, a day after a clean 1.11.21 bait version. Mastra packages carrying it as a dependency followed from about 01:12 UTC.
- Package counts differ by source: Microsoft and Socket say more than 140, SafeDep 143, and Orca 144 (142 packages in the @mastra scope plus mastra and create-mastra). Mastra's co-founder cited 116 malicious packages in his first statement.
- The publishing identity was ehindero, a real former contributor whose scope access, according to SafeDep, was never revoked. SafeDep saw an email change on the account, a sign of takeover.
- The payload ran at install time, disabled TLS checks, fetched a second stage from attacker servers, installed persistence and targeted more than 160 cryptocurrency wallet browser extensions, according to Socket.
- Lesson: every identity that can publish your packages is a production credential. Offboard contributors from registries, require MFA or trusted publishing for releases, and alert on releases that bypass your CI pipeline.
At a glance
| Organisation | Mastra (mastra-ai), maintainer of the mastra and @mastra npm packages; developers and CI systems that installed affected versions |
|---|---|
| When | Bait package published 16 June 2026; malicious publishing on 17 June 2026 (UTC) |
| Attacker | Sapphire Sleet (also known as BlueNoroff), a North Korean state actor, according to Microsoft Threat Intelligence (high confidence) |
| Entry point | Takeover of the ehindero npm maintainer account, a former contributor with publish rights across the Mastra scope |
| Identities abused | Former contributor's npm account and publishing token; attacker-created npm account sergey2016; on victim machines, any credentials the second stage could reach, with wallet extensions a stated target |
| Impact | More than 140 packages republished with a malicious dependency (counts range from 116 to 144 by source); combined weekly downloads above 1.1 million according to StepSecurity |
| Category | NHI (publishing identities and tokens), software supply chain, AI agent framework |
What happened
The preparation started with a separate package. On 16 June 2026 at 07:05 UTC, an npm account called sergey2016 published [email protected], a clean copy of the widely used dayjs date library, according to Microsoft and Socket. Socket describes this as establishing a benign history. At 01:01 UTC on 17 June, the same account published [email protected], which added a postinstall hook that runs an obfuscated file, setup.cjs.
Minutes later, the ehindero account began republishing Mastra packages. Each new version added a single production dependency, easy-day-js ^1.11.21. SafeDep points out that the caret range meant npm resolved the newest matching version, the poisoned 1.11.22, even though the range named the clean one. Microsoft says all poisoned Mastra versions were tagged "latest", so anyone installing or updating without a pinned version received them.
Sources give slightly different windows. StepSecurity says that "Over the next 88 minutes, 140+ packages across the entire Mastra ecosystem were republished", from 01:12 to 02:39 UTC. Socket puts the publishing "between roughly 01:15 and 02:36 UTC". Mastra co-founder Sam Bhagwat, quoted by Decipher, said that between 6:12 PM and 6:37 PM Pacific time, "a token associated with their account published 116 malicious packages, almost all in the @mastra/ namespace."
The account behind the release was not a stranger. SafeDep describes ehindero as "a real former Mastra contributor whose scope access was never revoked", which had published clean alpha versions between November 2024 and February 2025. The June releases came from a different email address from the contributor's original one, which SafeDep reads as account takeover rather than insider action. Microsoft says "The compromise originated from the takeover of the ehindero npm maintainer account, which had publish rights across the Mastra ecosystem." Bhagwat's summary was blunt: "The root cause is that one of our maintainers was compromised." In a Mastra podcast episode published on 26 June, the team discussed how the attackers gained access "via a fake Teams call"; the episode page does not give further detail.
Mastra's legitimate releases were built with SLSA provenance attestations, according to SafeDep, while the malicious ones lacked them. npm did not require provenance, so the difference was detectable but not enforced.
The payload itself was a two-stage loader. Socket reports that setup.cjs "disables TLS verification, fetches a second-stage payload from attacker-controlled infrastructure" and then deletes itself. The second stage, a roughly 41 KB Node.js client, installs login persistence, beacons to the operator and runs whatever code comes back. Socket says it targets "over 160 cryptocurrency wallet browser extensions", including MetaMask, Phantom and Coinbase Wallet, and collects browser history and host details. Microsoft adds that the implant establishes persistence through registry Run keys, macOS LaunchAgents and systemd, and describes reflective .NET assembly loading and PowerShell backdoor delivery on Windows.
Socket says it flagged easy-day-js "within six minutes after publication". Bhagwat said "we have unpublished or deprecated the relevant package versions." Decipher reports that Mastra disabled token-based npm publishing and now requires MFA for all publishes.
Timeline
| Date | Event |
|---|---|
| November 2024 to February 2025 | ehindero publishes clean alpha versions of Mastra packages as a contributor, according to SafeDep. |
| 16 June 2026, 07:05 UTC | sergey2016 publishes [email protected], a clean dayjs lookalike. |
| 17 June 2026, 01:01 UTC | [email protected] published with a malicious postinstall hook. |
| 17 June 2026, about 01:12 UTC | ehindero begins republishing Mastra packages with easy-day-js added (StepSecurity; Socket says about 01:15). |
| 17 June 2026, 02:36 to 02:39 UTC | Last malicious Mastra versions published, per Socket and StepSecurity respectively. |
| 17 June 2026 | Researchers including Socket, StepSecurity and SafeDep publish analyses; Mastra confirms the attack and pulls affected versions. |
| 18 to 19 June 2026 | Microsoft publishes its analysis attributing the campaign to Sapphire Sleet, then updates it. |
| 26 June 2026 | Mastra publishes a podcast episode on the incident, citing a fake Teams call as the route to access. |
How it happened: the identity attack path
- A dormant publishing identity. ehindero last published legitimate Mastra releases in early 2025, yet the account kept publish rights across the whole scope. Nobody had removed it when the contributor moved on.
- Account takeover. The attacker took control of the account; SafeDep observed its email changed to a new address. Mastra's own account of the route in points to a social engineering call, and Bhagwat said a token associated with the account did the publishing.
- A second, attacker-owned identity. The sergey2016 account published the lookalike dependency, first clean and then weaponised, so the Mastra packages themselves contained only a one-line dependency change.
- Publishing outside the pipeline. The malicious versions were published without the provenance attestations that Mastra's normal CI releases carried.
- Install-time execution. The postinstall hook ran on every workstation and CI runner that resolved the new version, whether or not the code imported it, as Microsoft notes.
- Persistence and theft. The second stage installed persistence and went after cryptocurrency wallets and host data, consistent with Sapphire Sleet's focus on the financial and crypto sectors described by Microsoft.
Impact
- Packages: Microsoft reports "140+ packages across the mastra and @mastra scopes"; SafeDep counts 143; Orca counts 144; SecurityWeek reported 141; Mastra's co-founder cited 116 in his first statement.
- Reach: StepSecurity says packages "with a combined weekly download count exceeding 1.1 million were exposed". Socket notes that @mastra/core alone has more than 918,000 weekly downloads, and SecurityWeek cited about 8 million weekly downloads across the affected packages.
- Exposure: Microsoft says any developer workstation or CI/CD pipeline that ran npm install or npm update after the compromised versions were published "was potentially exposed". Orca advises treating affected systems as fully compromised.
- Data taken: no public source we reviewed quantifies what was actually stolen. StepSecurity notes that Mastra environments typically hold LLM API keys, cloud credentials and CI secrets, which makes rotation essential even though the confirmed targeting focused on wallets.
What this means for NHI governance
The Mastra attack did not need a vulnerability. It needed one identity that could still publish. A contributor who had stopped releasing more than a year earlier kept rights over every package in the scope, and whatever token or session sat behind that account was enough to push 140 or more releases in a short burst. This is the software registry equivalent of an orphaned service account: an identity with broad write access, no active owner and nobody watching it.
Package publishing rights rarely appear in identity inventories. They live in npm organisation settings, not in the identity provider, so joiner, mover and leaver processes do not reach them. When a contributor leaves, their GitHub access may be reviewed but their registry role often is not. The Coupang signing key breach showed the same pattern with a signing key that outlived an employee.
The attack also shows why provenance must be enforced, not just produced. Mastra's real releases carried attestations; the malicious ones did not. A consumer policy that rejected unattested versions of packages that normally carry them, or a registry rule that allowed publishing only through the project's trusted CI identity, would have blocked this path. Finally, the target was an AI agent framework. Environments that build agents tend to hold LLM API keys, cloud credentials and tool tokens, so a compromise of the framework is a direct route to the non-human identities those agents run on.
Recommendations
- Offboard contributors from package registries. Review npm organisation and scope membership regularly and remove anyone who no longer publishes. Tie registry roles to the same leaver process as other access, as described in the Joiner, Mover, Leaver Guide.
- Publish only through CI. Use trusted publishing from a protected release workflow, disable long-lived publish tokens and require MFA for any manual publish, as Mastra has now done. The CI/CD Pipeline Identity Security Guide covers the controls.
- Enforce provenance as a consumer. Alert on or block new versions of dependencies that suddenly lack provenance attestations, and track what AI frameworks and components you depend on, following the AI Supply Chain Security and AI-BOM Guide.
- Disable install scripts by default. Run
npm install --ignore-scriptsin CI where possible, as Microsoft recommends, and pin exact versions with a lockfile rather than caret ranges for new dependencies. - Delay brand-new releases. A cooldown before new versions are consumed would have kept [email protected] out, since it was published minutes before the Mastra wave.
- Rotate what the host could reach. If an affected version was installed, remove persistence first, then rotate LLM API keys, cloud keys, CI secrets and tokens, and move wallet funds. The Secrets Management Guide explains how to keep these credentials short-lived.
Frequently asked questions
What happened in the Mastra npm supply chain attack?
On 17 June 2026, an attacker used the hijacked npm account of a former Mastra contributor to republish more than 140 Mastra packages with a malicious dependency, easy-day-js, whose install script downloaded a remote access trojan and cryptocurrency stealer.
Who was behind the Mastra npm attack?
Microsoft Threat Intelligence assesses with high confidence that the activity is attributable to Sapphire Sleet, a North Korean state actor also known as BlueNoroff, which it also links to an npm compromise of Axios in April 2026.
Were 144 packages compromised in 88 minutes?
Both figures come from specific sources. Orca counts 144 packages (142 in the @mastra scope plus two top-level packages) and StepSecurity describes an 88-minute window from 01:12 to 02:39 UTC. Other researchers count 140 to 143 packages, and Mastra's co-founder cited 116 packages in a shorter window.
Related NHI Mgmt Group resources
ChainDrop npm worm 2026 · Shai-Hulud npm campaign · Malicious Nx package attack · AI Coding Agents Security Guide · NHI breaches
How NHI Mgmt Group can help
Publishing tokens, registry roles and the API keys that AI agent frameworks depend on are non-human identities that need owners, reviews and offboarding like any other. Our NHI Foundation Level Training Course gives teams a practical way to find and govern them.
References
- Microsoft Security Blog: From package to postinstall payload, inside the Mastra npm supply chain compromise by Sapphire Sleet (18 June 2026, updated 19 June 2026)
- Socket: 140+ Mastra npm Packages Compromised in Coordinated Supply Chain Attack (17 June 2026)
- StepSecurity: Mastra npm Supply Chain Attack, 140+ Packages Backdoored via easy-day-js Typosquat (17 June 2026)
- SafeDep: Mastra npm Scope Takeover, 143 Packages Drop a RAT (17 June 2026)
- Orca Security: 144 Mastra npm Packages Compromised via Supply Chain Attack (17 June 2026)
- Decipher: Mastra AI Hit By npm Compromise (17 June 2026)
- SecurityWeek: North Korean Hackers Blamed for Mastra NPM Supply Chain Attack (22 June 2026)
- Mastra: Mastra Got Hacked. Here's What We Learned (podcast) (26 June 2026)