Reviewed threat campaign

Mastra AI framework npm compromise

Socket documented a June 2026 compromise of more than 140 packages in the @mastra npm scope where a typosquatted dependency with a postinstall payload was injected into published package manifests.

Severity highConfidence highReviewed 2026-08-09Expires 2026-09-08

Uncertainty

This record uses the reviewed June 17 investigation and does not infer the total number of affected developer machines or credentials from package download counts.

Limitations

Timeline

  1. · Mastra AI framework npm compromise was first observed in the reviewed source material.
  2. · The reviewed source published or updated its defensive analysis and remediation guidance.

Publication clock: 1280.9 hours from reviewed disclosure timestamp to HOL publication; 24-hour high target; historical backfill outside target.

Guard coverage and non-coverage

Defensive policy guidance

Sources