< Back to all clusters
[TECHNOLOGY] · Germany · 2 sources

Mastra npm and Arch Linux AUR hit by large-scale supply-chain attacks

In mid‑June 2026 attackers exploited a never‑revoked npm account to inject a malicious dependency into 144 packages of the Mastra AI‑framework namespace. The poisoned packages delivered a credential‑stealing loader that harvested browser histories, cryptocurrency‑wallet data and other secrets. The compromise window lasted just 88 minutes, exposing more than 1.1 million weekly downloads of @mastra packages.

A separate supply‑chain breach, dubbed “Atomic Arch”, began on 11 June 2026 against the Arch User Repository (AUR). Over 1 500 AUR packages were hijacked by taking control of abandoned packages and altering their build scripts to steal SSH keys, GitHub tokens, Docker credentials and browser cookies. The attack unfolded in three waves, with the final wave using AI‑generated exploits and rootkits to remain hidden. Both incidents underline the dangers of unrevoked access rights and the growing use of AI tools in cyber‑attacks, prompting calls for stricter provenance checks, automated off‑boarding of contributors, and broader adoption of SBOMs.