Jenn GileHost
Paul McCartyHost
it is a great week okay on to the meat of things um two days ago my time one day you go your time uh we saw a large account takeover in progress um threat actors hijacked the entirety of the Mastra organization, which is 116 packages.

And very similar to what we saw a couple months ago with the Axios compromise, they didn't actually put the malware in any of the Mastra packages.

What they did is they pre-staged a typosquatted package, an easy Easy node JS, easy something JS.

So like what we see with a lot of malware, they copied an existing legitimate package, kept everything, and just gave it a snappier name.

And then once they executed their takeover on Mastra, All they had to do was add this as a new dependency for all those packages.

It is almost stage per stage, step per step, the same as the Axios attack, including the initial compromise of the account came through a social engineering company.

very targeted spear phishing type thing where the maintainer like something that, you know, click fix style kind of a, Hey, there's something wrong with your microphone.

I think it's a really great analysis because you went deep into the similarities between the two attacks, a little bit about the potential threat actor, which we will say anyone who's saying they know who this is, we're a little skeptical.

We don't have a confirmed um attribution and then uh what it's targeting i think is really interesting so have at it i'll

stop me too um listen first and foremost there's a lot of other great write-ups from step security and aikido and a bunch of other companies and mad respect to them right um this was an opportunity for me to do to go deep like i used to do all the time before i you know was building a startup and a business and you know all these things that we're doing now right but so it was nice it was a blast from the past for me able to go super deep on something but um yeah so a couple things first um i didn't know that the actual um the compromise was was happened the way you said it because i know there was a couple there's contemporaneous like there was a couple of people that were talking on twitter about So my source

It could be better, but there's a pretty decent retrospective incident report on it, on their GitHub issues for someone who's with the company.

it is a great week okay on to the meat of things um two days ago my time one day you go your time uh we saw a large account takeover in progress um threat actors hijacked the entirety of the Mastra organization, which is 116 packages.

And very similar to what we saw a couple months ago with the Axios compromise, they didn't actually put the malware in any of the Mastra packages.

What they did is they pre-staged a typosquatted package, an easy Easy node JS, easy something JS.

So like what we see with a lot of malware, they copied an existing legitimate package, kept everything, and just gave it a snappier name.

And then once they executed their takeover on Mastra, All they had to do was add this as a new dependency for all those packages.

It is almost stage per stage, step per step, the same as the Axios attack, including the initial compromise of the account came through a social engineering company.

very targeted spear phishing type thing where the maintainer like something that, you know, click fix style kind of a, Hey, there's something wrong with your microphone.

I think it's a really great analysis because you went deep into the similarities between the two attacks, a little bit about the potential threat actor, which we will say anyone who's saying they know who this is, we're a little skeptical.

We don't have a confirmed um attribution and then uh what it's targeting i think is really interesting so have at it i'll

stop me too um listen first and foremost there's a lot of other great write-ups from step security and aikido and a bunch of other companies and mad respect to them right um this was an opportunity for me to do to go deep like i used to do all the time before i you know was building a startup and a business and you know all these things that we're doing now right but so it was nice it was a blast from the past for me able to go super deep on something but um yeah so a couple things first um i didn't know that the actual um the compromise was was happened the way you said it because i know there was a couple there's contemporaneous like there was a couple of people that were talking on twitter about So my source

It could be better, but there's a pretty decent retrospective incident report on it, on their GitHub issues for someone who's with the company.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.