INTEL_REPORT
Snyk Blog — AppSec & supply chain · published 6/16/2026, 9:00:00 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope A dormant contributor account was used to republish the entire @mastra npm scope, each injected with a single dependency, easy-day-js, that drops a cross-platform cryptocurrency stealer. Here is how the attack worked, how to check exposure, and how to remediate. Mastra npm Scope Takeover | Snyk You need to enable JavaScript to run this app. Skip to main content Platform Platform Snyk AI Security…
https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope
sha256:ec26912f61dd83d5a4f6c3e010faa731772c2cc058688305d116ccf866a04af1
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| plus.probely.app |
| Open → |
| domain | yarn.lock | Open → |
| domain | pnpm-lock.yaml | Open → |
| ip | 23.254.164.92 | Open → |
| ip | 23.254.164.123 | Open → |
| ip | 23.254.164.0 | Open → |
| domain | tutamail.com | Open → |
| domain | setup.cjs | Open → |
| domain | www.wolfssl.com | Open → |
| domain | com.nvm.protocal.plist | Open → |
| domain | nvmconf.service | Open → |
| url | https://23.254.164.92:8000/update/49890878 | Open → |
| sha256 | 221c45a790dec2a296af57969e1165a16f8f49733aeab64c0bbd768d9943badf | Open → |