Mastra AI Hit By npm Compromise
The unknown threat actor gained unauthorized access to legitimate npm accounts, allowing them to inject malicious dependencies into widely used packages.
All topics
The unknown threat actor gained unauthorized access to legitimate npm accounts, allowing them to inject malicious dependencies into widely used packages.
Researchers said that they found a Red Hat employee's GitHub account had been compromised and was used by threat actors to push malicious orphan commits directly to several repositories.
The disruption, which was a joint effort among CrowdStrike, Google, and the Shadowserver Foundation, targeted Glassworm’s C2 architecture, which was deliberately engineered for extreme resilience.
In the spring, a young attacker’s fancy turns to supply chain compromises, and this season’s crop includes the GitHub breach and the Grafana intrusion, which are connected and trace back to the TanStack supply chain attack and…TeamPCP.
The company said it is still working through the intrusion but does not believe any customer repositories or data was affected at this point.
As of May 2026, over 6,502 ATG services running on 6,057 unique hosts were found to be reachable on the public internet across more than 65 countries.