1

Mais de 140 pacotes da Mastra no npm, com mais de 28 milhões de downloads mensais, são comprometidos com malware em ataque à cadeia de suprimentos

O script malicioso “easy-day-js”, adicionado pelo invasor como dependência das bibliotecas, coleta histórico do navegador e dados armazenados em mais de 160 extensões de carteiras de criptomoedas, além de chaves de API, tokens do GitHub, NPM e credenciais de provedores de nuvem. Abaixo, há uma lista com as versões infectadas, a maioria já removida do repositório.


PacoteVersão
@mastra/acp0.2.2
@mastra/agent-browser0.3.2
@mastra/agent-builder1.0.42
@mastra/agentcore0.2.2
@mastra/agentfs0.1.1
@mastra/ai-sdk1.4.6
@mastra/arize1.2.3
@mastra/arthur0.3.3
@mastra/astra1.0.2
@mastra/auth1.0.3
@mastra/auth-auth01.0.2
@mastra/auth-better-auth1.0.4
@mastra/auth-clerk1.0.3
@mastra/auth-cloud1.1.4
@mastra/auth-firebase1.0.1
@mastra/auth-okta0.0.5
@mastra/auth-studio1.2.4
@mastra/auth-supabase1.0.2
@mastra/auth-workos1.5.3
@mastra/azure0.2.3
@mastra/blaxel0.4.2
@mastra/braintrust1.1.4
@mastra/brightdata0.2.2
@mastra/browser-firecrawl0.1.1
@mastra/browser-viewer0.1.3
@mastra/chroma1.0.2
@mastra/claude1.0.3
@mastra/clickhouse1.10.1
@mastra/client-js1.24.1
@mastra/cloud0.1.24
@mastra/cloudflare1.4.2
@mastra/cloudflare-d11.0.7
@mastra/codemod1.0.4
@mastra/convex1.2.2
@mastra/core1.42.1
@mastra/couchbase1.0.4
@mastra/cursor0.2.1
@mastra/dane1.0.2
@mastra/datadog1.2.5
@mastra/daytona0.4.2
@mastra/deployer1.42.1
@mastra/deployer-cloud1.42.1
@mastra/deployer-cloudflare1.1.44
@mastra/deployer-netlify1.1.20
@mastra/deployer-vercel1.1.38
@mastra/docker0.3.1
@mastra/dsql1.0.3
@mastra/duckdb1.4.3
@mastra/dynamodb1.0.9
@mastra/e2b0.3.4
@mastra/editor0.11.3
@mastra/elasticsearch1.2.1
@mastra/engine0.1.1
@mastra/evals1.3.1
@mastra/express1.3.31
@mastra/fastembed1.1.3
@mastra/fastify1.3.31
@mastra/files-sdk0.2.1
@mastra/gcs0.2.3
@mastra/github-signals0.1.2
@mastra/google-cloud-pubsub1.0.6
@mastra/google-drive0.1.1
@mastra/hono1.4.26
@mastra/inngest1.5.2
@mastra/koa1.5.14
@mastra/laminar1.2.3
@mastra/lance1.0.7
@mastra/langfuse1.3.6
@mastra/langsmith1.2.4
@mastra/libsql1.13.1
@mastra/loggers1.1.3
@mastra/longmemeval1.0.50
@mastra/mcp1.10.1
@mastra/mcp-docs-server1.1.47
@mastra/mcp-registry-registry1.0.2
@mastra/mem00.1.14
@mastra/memory1.20.4
@mastra/modal0.2.2
@mastra/mongodb1.9.3
@mastra/mssql1.3.2
@mastra/mysql0.1.1
@mastra/nestjs0.1.15
@mastra/node-audio0.1.8
@mastra/node-speaker0.1.1
@mastra/observability1.14.2
@mastra/openai1.0.2
@mastra/opencode0.0.47
@mastra/opensearch1.0.3
@mastra/otel-bridge1.2.3
@mastra/otel-exporter1.2.3
@mastra/perplexity0.1.1
@mastra/pg1.13.1
@mastra/pinecone1.0.2
@mastra/playground-ui33.0.1
@mastra/posthog1.0.29
@mastra/qdrant1.0.3
@mastra/rag2.2.2
@mastra/railway0.1.1
@mastra/react1.0.1
@mastra/redis1.1.3
@mastra/redis-streams0.0.4
@mastra/s30.5.3
@mastra/s3vectors1.0.7
@mastra/schema-compat1.2.12
@mastra/sentry1.1.4
@mastra/server2.1.1
@mastra/slack1.3.1
@mastra/spanner1.1.2
@mastra/speech-azure0.2.1
@mastra/speech-elevenlabs0.2.1
@mastra/speech-google0.2.1
@mastra/speech-ibm0.2.1
@mastra/speech-murf0.2.1
@mastra/speech-openai0.2.1
@mastra/speech-replicate0.2.1
@mastra/speech-speechify0.2.1
@mastra/stagehand0.2.5
@mastra/tavily1.0.3
@mastra/temporal0.1.14
@mastra/turbopuffer1.0.3
@mastra/twilio1.0.2
@mastra/upstash1.1.3
@mastra/vectorize1.0.3
@mastra/vercel1.0.1
@mastra/voice-aws-nova-sonic0.1.4
@mastra/voice-azure0.11.2
@mastra/voice-cloudflare0.12.3
@mastra/voice-deepgram0.12.2
@mastra/voice-elevenlabs0.12.2
@mastra/voice-gladia0.12.2
@mastra/voice-google0.12.3
@mastra/voice-google-gemini-live0.12.2
@mastra/voice-inworld0.3.1
@mastra/voice-modelslab0.1.2
@mastra/voice-murf0.12.3
@mastra/voice-openai0.12.3
@mastra/voice-openai-realtime0.12.6
@mastra/voice-playai0.12.2
@mastra/voice-sarvam1.0.2
@mastra/voice-speechify0.12.2
@mastra/voice-xai-realtime0.1.2
create-mastra1.13.1
mastra1.13.1
Carregando publicação patrocinada...