Crow's Nest - 2026-06-22
A roundup of 126 items curated from across the security community. News Mastra-AI npm Supply Chain Attack Hits 80+ Packages by Dave Kennedy. An attacker hijacked npm accounts to inject a phantom dependency into 80+ Mastra-AI packages. The malicious payload arrived via a “dayjs” typosquat that ran a post-install script to download and execute a remote binary. Operation Endgame Dismantles SocGholish Infrastructure by SwitHak (). International law enforcement took down 100 servers and domains, remediating nearly 15,000 websites. SocGholish’s “FakeUpdates” web inject framework has been a persistent ransomware delivery vector since 2018. ...
