Your RSA-2048 keys break in 2030. Find every one of them before attackers do.See CBOMkit
@mastra
The @mastra scope on npm published 89 malicious packages. See the full package list, affected versions, and how to check whether your dependency tree pulled any of them in.
Malicious packages
89
Advisories
89
Ecosystem
npm
First seen
2026-06-17
What to do if you depend on any of these
Every package below was published as malicious under @mastra. Treat any machine that installed one as compromised: remove the package and its lockfile entry, rotate every credential the build or runtime could reach (registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values) from a known-clean machine, and audit for unexpected outbound activity.
Because the packages share a publisher scope, a project that pulled in one has an elevated chance of having pulled in others. Search your lockfiles for @mastra rather than checking a single package name.
All 89 packagesnpm
- @mastra/agent-browserView advisory →
- @mastra/agent-builderView advisory →
- @mastra/ai-sdkView advisory →
- @mastra/arizeView advisory →
- @mastra/authView advisory →
- @mastra/auth-auth0View advisory →
- @mastra/auth-better-authView advisory →
- @mastra/auth-clerkView advisory →
- @mastra/auth-supabaseView advisory →
- @mastra/auth-workosView advisory →
- @mastra/blaxelView advisory →
- @mastra/braintrustView advisory →
- @mastra/chromaView advisory →
- @mastra/claudeView advisory →
- @mastra/clickhouseView advisory →
- @mastra/client-jsView advisory →
- @mastra/cloudflareView advisory →
- @mastra/cloudflare-d1View advisory →
- @mastra/convexView advisory →
- @mastra/coreView advisory →
- @mastra/couchbaseView advisory →
- @mastra/cursorView advisory →
- @mastra/datadogView advisory →
- @mastra/daytonaView advisory →
- @mastra/deployerView advisory →
- @mastra/deployer-cloudflareView advisory →
- @mastra/deployer-netlifyView advisory →
- @mastra/deployer-vercelView advisory →
- @mastra/dockerView advisory →
- @mastra/dsqlView advisory →
- @mastra/duckdbView advisory →
- @mastra/dynamodbView advisory →
- @mastra/e2bView advisory →
- @mastra/editorView advisory →
- @mastra/evalsView advisory →
- @mastra/expressView advisory →
- @mastra/fastembedView advisory →
- @mastra/fastifyView advisory →
- @mastra/gcsView advisory →
- @mastra/github-signalsView advisory →
- @mastra/google-cloud-pubsubView advisory →
- @mastra/honoView advisory →
- @mastra/inngestView advisory →
- @mastra/koaView advisory →
- @mastra/langfuseView advisory →
- @mastra/langsmithView advisory →
- @mastra/libsqlView advisory →
- @mastra/loggersView advisory →
- @mastra/longmemevalView advisory →
- @mastra/mcpView advisory →
- @mastra/mcp-docs-serverView advisory →
- @mastra/mcp-registry-registryView advisory →
- @mastra/mem0View advisory →
- @mastra/memoryView advisory →
- @mastra/mongodbView advisory →
- @mastra/mssqlView advisory →
- @mastra/nestjsView advisory →
- @mastra/node-audioView advisory →
- @mastra/node-speakerView advisory →
- @mastra/observabilityView advisory →
- @mastra/otel-bridgeView advisory →
- @mastra/otel-exporterView advisory →
- @mastra/pgView advisory →
- @mastra/pineconeView advisory →
- @mastra/playground-uiView advisory →
- @mastra/posthogView advisory →
- @mastra/qdrantView advisory →
- @mastra/ragView advisory →
- @mastra/reactView advisory →
- @mastra/redisView advisory →
- @mastra/s3View advisory →
- @mastra/s3vectorsView advisory →
- @mastra/schema-compatView advisory →
- @mastra/sentryView advisory →
- @mastra/serverView advisory →
- @mastra/stagehandView advisory →
- @mastra/tavilyView advisory →
- @mastra/temporalView advisory →
- @mastra/turbopufferView advisory →
- @mastra/upstashView advisory →
- @mastra/vectorizeView advisory →
- @mastra/voice-aws-nova-sonicView advisory →
- @mastra/voice-deepgramView advisory →
- @mastra/voice-elevenlabsView advisory →
- @mastra/voice-googleView advisory →
- @mastra/voice-google-gemini-liveView advisory →
- @mastra/voice-openaiView advisory →
- @mastra/voice-openai-realtimeView advisory →
- @mastra/voice-playaiView advisory →