Back to all episodes

Mastra Got Hacked. Here's What We Learned

June 26, 2026

Mastra got hacked. In this special edition of Security Corner, Shane Thomas and Abhi Aiyer break down exactly what happened when a supply chain attack hit Mastra's npm packages — an attack that appears to trace back to hackers in North Korea. They're joined by Ismail Pelaseyed, co-founder and CTO of Superagent, for the outside view on how these campaigns actually work.

Guests in this episode

Ismail Pelaseyed

Ismail Pelaseyed

Superagent

Watch on

Episode Transcript

0:00

Intro: a special Security Corner

0:55

The supply chain attack on Mastra

1:29

How they got in: a fake Teams call

2:27

The npm account takeover

3:54

EasyDjS and the scramble to fix it

5:49

Why success makes you a target

9:20

How AI supercharges phishing

9:59

Hardening against compromised contributors

11:10

Open source under strain: IBM's $5B bet

12:27

npm and PyPI keep dropping the ball

14:31

Inside the fake package, and how Socket caught it

16:20

The fear-selling problem in security

18:02

Superagent!