Reviewed threat campaign
Mastra AI framework npm compromise
Socket documented a June 2026 compromise of more than 140 packages in the @mastra npm scope where a typosquatted dependency with a postinstall payload was injected into published package manifests.
Uncertainty
This record uses the reviewed June 17 investigation and does not infer the total number of affected developer machines or credentials from package download counts.
Limitations
- Treat lockfile review, registry advisories, secret rotation, and endpoint investigation as complementary controls.
Timeline
- · Mastra AI framework npm compromise was first observed in the reviewed source material.
- · The reviewed source published or updated its defensive analysis and remediation guidance.
Publication clock: 1280.9 hours from reviewed disclosure timestamp to HOL publication; 24-hour high target; historical backfill outside target.
Guard coverage and non-coverage
- partial: coverage:stable:codex — Guard can require review for eligible dependency installation actions, but the stable manifest does not claim complete coverage for every transitive resolver path or already-running postinstall payload.
Defensive policy guidance
- Require review or explicit approval for new or changed dependency installation before an eligible package-manager action executes.
Status: available. Coverage depends on the active Guard release, package manager, harness event surface, and local policy. It is not a guarantee that every dependency path is intercepted.
Sources
- Socket: Mastra npm package compromise · observed 2026-08-09