@mastra/evals
MAL-2026-5947
npmmalware6/17/2026
Description
Malicious code in @mastra/evals (npm)
Indicators of Compromise
SHA256 Hashes (1)
d54f073f0d2ca3dc2620f0269e930084da1e62f637d51b1082a95f7ed0e549fa
References (1)
Details
Ecosystemnpm
Attack Typemalware
Published6/17/2026
Aliases
GHSA-c9hm-w6m5-hwcj
Quick Actions