A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope
A dormant contributor account was hijacked to republish every package in the @mastra npm scope with an injected crypto-stealer dependency, illustrating how forgotten accounts with residual publish rights become the weakest link in scope ownership.
Summary written by editorial AI · Source link below
A dormant contributor account was used to republish the entire @mastra npm scope, each injected with a single dependency, easy-day-js, that drops a cross-platform cryptocurrency stealer. Here is how the attack worked, how to check exposure, and how to remediate.
Editorial Analysis
Dormant accounts with residual publishing permissions are a systemic blind spot; enterprise teams must treat contributor lifecycle management as a critical supply-chain control.
Review npm org membership for dormant or former contributor accounts with publish access, and enforce MFA plus periodic access recertification.
An abandoned developer account was exploited to inject malware across an entire npm scope—dormant access rights are a supply-chain liability.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at Snyk Blog in a new tab.
More from the DevSecOps Desk
- Boundary-Mutation Testing for Pattern-Based Secret Detection: A Rule-Level Method and Cross-Scanner Evaluation4d
- PatchBench: Evaluating AI Agents for Vulnerability Patching4d
- Coder's registry infrastructure compromised to push malicious modules4d
- Modelstamp: Pre-Deserialization Verification of Machine-Learning Artifacts and Runtime Environment State5d
- Barriers to Using Static Application Security Testing (SAST) Tools: A Literature Review5d