<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>npm - Developers Digest</title>
    <link>https://www.developersdigest.tech/blog/tags/npm</link>
    <description>Articles about npm on Developers Digest</description>
    <language>en</language>
    <lastBuildDate>Wed, 17 Jun 2026 17:23:20 GMT</lastBuildDate>
    <atom:link href="https://www.developersdigest.tech/blog/tags/npm/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title><![CDATA[Mastra npm Supply Chain Attack: 140+ AI Framework Packages Backdoored]]></title>
      <link>https://www.developersdigest.tech/blog/mastra-npm-supply-chain-attack-2026</link>
      <guid isPermaLink="true">https://www.developersdigest.tech/blog/mastra-npm-supply-chain-attack-2026</guid>
      <description><![CDATA[On June 17, 2026, attackers hijacked a dormant Mastra contributor account and pushed malicious versions of 140+ packages. The payload steals crypto wallets, browser data, and cloud credentials. Here is what happened, how to check your lockfile, and what to do if you installed an affected version.]]></description>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>npm</category>
      <category>supply-chain</category>
      <category>mastra</category>
      <category>ai-agents</category>
      
    </item>
  </channel>
</rss>