TI Mindmap HUB
Threat Intelligence Report

140+ Mastra npm Packages Compromised in Coordinated Supply Chain Attack

๐Ÿ“… June 17, 2026 ๐Ÿ“ฐ socket.dev ๐Ÿ” 0 CVE(s) referenced

A coordinated supply chain attack compromised over 140 Mastra npm packages by injecting a malicious dependency that, upon installation, deployed a cross-platform infostealer capable of exfiltrating browser history and cryptocurrency wallet data, establishing persistent access, and enabling arbitrary remote code execution on developer and CI systems.

vendor

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

๐Ÿ” Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

๐Ÿ“Š Visual Mindmap
๐ŸŽฏ IOC Extraction
โš”๏ธ MITRE ATT&CK TTPs
๐Ÿ“ฆ STIX 2.1 Bundle