high severityConfidence highHistorical record

Mastra AI framework npm compromise

Socket documented a June 2026 compromise of more than 140 packages in the @mastra npm scope where a typosquatted dependency with a postinstall payload was injected into published package manifests.

Also tracked as Mastra AI framework compromise

First observed
Jun 17, 2026
Last observed
Jun 17, 2026
Last reviewed
Sep 13, 2026
Tracking ended
Sep 8, 2026

Uncertainty and limitations

Read the evidence limits before acting on this record.

This record uses the reviewed June 17 investigation and does not infer the total number of affected developer machines or credentials from package download counts.

  • Treat lockfile review, registry advisories, secret rotation, and endpoint investigation as complementary controls.

Guard coverage and policy

What Guard's reviewed assertions do and do not claim for this campaign, and the reviewed starting points for defense.

Not covered, or partially covered

  • partial

    Guard can require review for eligible dependency installation actions, but the stable manifest does not claim complete coverage for every transitive resolver path or already-running postinstall payload.

  • Recipe available

    Require review or explicit approval for new or changed dependency installation before an eligible package-manager action executes.

    Coverage depends on the active Guard release, package manager, harness event surface, and local policy. It is not a guarantee that every dependency path is intercepted.

Safe next step. Campaign guidance is defensive context. It does not auto-apply policy or claim universal campaign coverage.

Timeline

Reviewed events, oldest first, each tied to a verified source.

  1. First observed

    Mastra AI framework npm compromise was first observed in the reviewed source material.

  2. Disclosure

    The reviewed source published or updated its defensive analysis and remediation guidance.

Publication clock: 1280.9 hours from reviewed disclosure timestamp to HOL publication; 24-hour high target; historical backfill outside target.

Reviewed artifacts

The specific artifacts this record concerns, as reviewed. Names and versions are shown as text; a registry link is not recorded here.

  • @mastra/* affected releasesnpmpackage
  • easy-day-js@1.11.22npmpackage

Sources

Every claim on this record is traceable to the sources below.

Reviewed in full by HOL Guard Research.

Published
Last full review
Last modified

Report a correction

Record HGTC-2026-MASTRAAI26