security: From package to postinstall payload: Inside the Mastra npm supply chain compromise
Microsoft Security Blog
2026-06-18
Microsoft describes a compromised npm package in the Mastra ecosystem that spread a hidden postinstall payload to 140+ projects. The post focuses on detection, hunting, and defense guidance using Microsoft Defender and threat intelligence.