Mastra Got Hacked. Here's What We Learned
Mastra got hacked. In this special edition of Security Corner, Shane Thomas and Abhi Aiyer break down exactly what happened when a supply chain attack hit Mastra's npm packages — an attack that appears to trace back to hackers in North Korea. They're joined by Ismail Pelaseyed, co-founder and CTO of Superagent, for the outside view on how these campaigns actually work.
Guests in this episode

Ismail Pelaseyed
SuperagentWatch on
Episode Transcript
Intro: a special Security Corner
The supply chain attack on Mastra
How they got in: a fake Teams call
The npm account takeover
EasyDjS and the scramble to fix it
Why success makes you a target
How AI supercharges phishing
Hardening against compromised contributors
Open source under strain: IBM's $5B bet
npm and PyPI keep dropping the ball
Inside the fake package, and how Socket caught it
The fear-selling problem in security
Superagent!
More episodes
- August 4, 2026Freestyle's CEO Runs His Cloud From a House — Ben Swerdlow on Agent VMsBenjamin Swerdlow
- July 30, 2026Opus 5 vs Fable, Rogue Model Hacks Hugging Face & the Open Weights Letter | This Week In AI
- July 29, 2026Is Gemini Actually a Coding Model? Google DeepMind's Ivan Leo AnswersIvan Leo
- July 24, 2026Is Ramp an AI Company Now? Plus Kimi K3 Beats Fable on Front-End | This Week In AI