Back in June a single developer with stolen credentials managed to publish malicious versions of more than 140 Mastra AI packages in under twenty minutes. Mastra is one of the most used frameworks for building AI agents in production. The poisoned releases went straight through npm, through the same channels as always, and anyone who installed during that window got exposed to malware hunting for crypto wallets and phoning home to a command-and-control server tied to a North Korea-linked group. This wasn't some sloppy typosquatting attempt, it was a legitimate maintainer account compromised right at the source.
https://chat-to.dev/post?id=NDFlZ3RoK3J1MnQwNFNiWGQ4c2ZqZz09
For further actions, you may consider blocking this person and/or reporting abuse
Top comments (0)