Mastra Got Hacked. Here's What We Learned
Mastra got hacked. In this special edition of Security Corner, Shane Thomas and Abhi Aiyer break down exactly what happened when a supply chain attack hit Mastra's npm packages — an attack that appears to trace back to hackers in North Korea. They're joined by Ismail Pelaseyed, co-founder and CTO of Superagent, for the outside view on how these campaigns actually work.
Guests in this episode

Ismail Pelaseyed
SuperagentWatch on
Episode Transcript
Intro: a special Security Corner
The supply chain attack on Mastra
How they got in: a fake Teams call
The npm account takeover
EasyDjS and the scramble to fix it
Why success makes you a target
How AI supercharges phishing
Hardening against compromised contributors
Open source under strain: IBM's $5B bet
npm and PyPI keep dropping the ball
Inside the fake package, and how Socket caught it
The fear-selling problem in security
Superagent!
More episodes
- September 9, 2026GPT-6 Astra vs Claude Fable 5.1, We Should Pause AI & The Benchmark Wars | This Week In AI
- September 8, 2026Multiplayer Coding Agents in the Cloud - Charlie Holtz, ConductorCharlie Holtz
- September 3, 2026OpenAI Cuts Off Cursor, Nvidia Buys Hugging Face, Ox Alpha is GLM | This Week In AI
- August 28, 2026Why Agents Are Actually Workflows - Tony Kovanen, Mastra's Founding Engineer