LWA-2026-5635 MAL-2026-6055 ↗ confirmed malware

@mastra/node-speaker@0.1.1

Malicious code in @mastra/node-speaker (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

This version is a hijacked re-publish of a previously-dormant native audio package (the prior release was clean; this one was pushed under a newly-changed, anonymous publisher account after ~15 months of inactivity). The only change from the last good version is an injected dependency on a date-library typosquat (easy-day-js). That dependency ships a postinstall hook that runs an obfuscated dropper: it disables TLS certificate verification, drops marker files in the user home directory, downloads a second-stage payload over HTTPS from a hardcoded raw-IP command-and-control server (23[.]254[.]164[.]92 on port 8000), writes it to a randomly-named .cjs file in the home directory, launches it as a detached background Node process, and then deletes its own installer script to hide evidence. Installing this package therefore results in remote code execution at install time via the transitive dependency.

analyzed by
Leitwacht
first seen
Jun 17, 2026, 02:29 AM
analyzed
Jun 17, 2026, 02:59 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.