{"schemaVersion":"guard-threat-campaign/v1","id":"HGTC-2026-MASTRAAI26","slug":"mastra-ai-framework-npm-compromise","title":"Mastra AI framework npm compromise","aliases":["Mastra AI framework compromise"],"summary":"Socket documented a June 2026 compromise of more than 140 packages in the @mastra npm scope where a typosquatted dependency with a postinstall payload was injected into published package manifests.","status":"published","severity":"high","confidence":"high","uncertainty":"This record uses the reviewed June 17 investigation and does not infer the total number of affected developer machines or credentials from package download counts.","firstObservedAt":"2026-06-17T01:15:00.000Z","lastObservedAt":"2026-06-17T02:36:00.000Z","publishedAt":"2026-08-09T11:30:00.000Z","reviewedAt":"2026-08-09T11:20:00.000Z","expiresAt":"2026-09-08T23:59:59.000Z","reviewer":"HOL Guard Research","sources":[{"id":"source:socket-mastra","label":"Socket: Mastra npm package compromise","url":"https://socket.dev/blog/mastra-npm-packages-compromised","sourceType":"other_primary","observedAt":"2026-08-09T11:20:00.000Z"}],"artifacts":[{"id":"artifact:mastra-scope","artifactClass":"package","ecosystem":"npm","name":"@mastra/* affected releases","version":null,"defanged":true},{"id":"artifact:easy-day-js","artifactClass":"package","ecosystem":"npm","name":"easy-day-js","version":"1.11.22","defanged":true}],"indicators":[],"timeline":[{"id":"timeline:first-observed","occurredAt":"2026-06-17T01:15:00.000Z","eventType":"first_observed","summary":"Mastra AI framework npm compromise was first observed in the reviewed source material.","sourceIds":["source:socket-mastra"]},{"id":"timeline:disclosure","occurredAt":"2026-06-17T02:36:00.000Z","eventType":"disclosure","summary":"The reviewed source published or updated its defensive analysis and remediation guidance.","sourceIds":["source:socket-mastra"]}],"coverage":[{"assertionId":"coverage:stable:codex","relationship":"partial","limitation":"Guard can require review for eligible dependency installation actions, but the stable manifest does not claim complete coverage for every transitive resolver path or already-running postinstall payload."}],"policies":[{"policyId":"policy:package-install-review","purpose":"Require review or explicit approval for new or changed dependency installation before an eligible package-manager action executes.","status":"available","limitation":"Coverage depends on the active Guard release, package manager, harness event surface, and local policy. It is not a guarantee that every dependency path is intercepted."}],"limitations":["Treat lockfile review, registry advisories, secret rotation, and endpoint investigation as complementary controls."],"correctionHref":"/guard/security/campaigns/mastra-ai-framework-npm-compromise/corrections"}