Mastra Supply Chain Attack: How Do CI/CD Pipelines Survive Malicious Dependencies?
Mastra Supply Chain Attack: How Do CI/CD Pipelines Survive Malicious Dependencies? TL;TR The recent Mastra Supply Chain Attack exposed a critical vulnerability in modern software development. Threat actors compromised over 144 packages within the Mastra npm ecosystem by injecting a malicious dependency called easy-day-js. This dependency utilized npm postinstall scripts to silently download remote access payloads during the standard build process. Because these actions occur