Register and share your invite link to earn from video plays and referrals.

SlowMist
@SlowMist_Team
SlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.
Joined April 2018
408 Following    88.8K Followers
🚨 SlowMist TI Alert 🚨 A coordinated npm supply chain attack affecting 140+ @mastra/* packages. The affected packages added a dependency on easy-day-js@^1.11.21, which can be automatically resolved during installation to the malicious version easy-day-js@1.11.22, triggering attacker-controlled code through an install-time hook. Potential attacker actions include install-time code execution, persistence on Windows/macOS/Linux, browser history collection, cryptocurrency wallet extension inventory, credential or CI secret exposure through follow-on tasking, and data exfiltration. Treat any system that installed affected @mastra/* versions as potentially compromised: remove malicious versions and easy-day-js, delete node_modules and package caches, reinstall known-clean versions with verified lockfiles, isolate impacted hosts, preserve logs, remove persistence artifacts, and rotate npm, GitHub, cloud, SSH/Git, CI/CD, and wallet-related credentials where exposure is possible. As always, stay vigilant!
Show more