TI Mindmap HUB
Threat Intelligence Report

Mastra NPM attack: A deep dive on the malware and what it targets

📅 June 18, 2026 📰 opensourcemalware.com 🔍 0 CVE(s) referenced

The June 2026 Mastra npm supply-chain attack leveraged a dormant maintainer account to inject a weaponized dependency across 140+ packages, deploying a cross-platform RAT that not only steals crypto-wallet credentials but also aggressively targets password managers, MFA authenticators, and even Zapier browser extensions—signaling a dangerous expansion in the victim profile for software supply-chain malware.

unclassified

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

🔐 Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

📊 Visual Mindmap
🎯 IOC Extraction
⚔️ MITRE ATT&CK TTPs
📦 STIX 2.1 Bundle