MAL-2026-6022

    Dashboard / Malicious Package / MAL-2026-6022

    MAL-2026-6022

    Published: 17 Jun 2026Last Modified: 9 Jul 2026Aliases: 
    GHSA-r6w3-xpw9-p9g6

    Summary: Malicious code in @mastra/express (npm)

    Details: Source: amazon-inspector (9cd00df32d6d56cd3d4996965ed13e18c1da3a9b0007392b4fc14da1a8fcbb46) The package's bundled distribution files (dist/index.cjs and dist/index.js) contain a `Buffer.from(..., 'base64').toString('utf-8')` decode pattern. This pattern by itself is benign and extremely common in JavaScript bundles — used for inline data URIs, JWT segment parsing, encoded SVG/PNG assets, configuration constants, and similar legitimate purposes. No corroborating evidence of credential theft, exfiltration, dropper behavior, lifecycle-script abuse, or hardcoded attacker infrastructure was observed. The match is on a single keyword pattern in a bundled main module with no traced harmful execution path. Source: ghsa-malware (c7375ba72b0d9da5bf4d20ab526cb654b97310e39965bea22eb5d3d0557961d4) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

    Affected packages

    Package

    Name: @mastra/express

    Purl: pkg:npm/%40mastra/express

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.3.31