Supply chain Mastra npm packages compromised in ‘easy-day-js’ supply chain attack June 17, 2026 Share By SC Staff (Adobe Stock) As many as 144 npm packages associated with the Mastra namespace have been compromised as part of a software supply chain attack named easy-day-js. The attack targeted popular open-source JavaScript and TypeScript framework packages used for building artificial intelligence applications. This incident was uncovered through findings from JFrog, SafeDep, Socket, and StepSecurity, as reported by The Hacker News. The attack involved the compromise of an npm account, which then mass-published over 140 malicious packages under the Mastra scope. The malicious code was not directly in the Mastra packages but was introduced via a third-party dependency named "easy-day-js." This library, initially published as clean, was later updated with malicious changes. The "easy-day-js" package executes an obfuscated payload during the postinstall hook, which acts as a dropper for a second-stage payload. This payload retrieves further malicious code from attacker-controlled infrastructure after disabling TLS certificate validation. The final payload is a cross-platform information stealer capable of harvesting browser data, cryptocurrency wallet information, and establishing persistence across Windows, macOS, and Linux systems before exfiltrating the data. The attackers reportedly hijacked a legitimate former Mastra contributor's account. NPM has since removed the malicious versions. Any system that installed the affected packages should be considered potentially compromised, and users are advised to roll back to safe versions, rotate credentials, and audit hosts. Source: The Hacker News SC Staff Related Critical Infrastructure Security AUR suspends new registrations as 1,500-plus malicious packages flood repository Laura French June 17, 2026 Malicious build scripts deploy a Rust-based infostealer and eBPF rootkit. Supply chain Malicious JetBrains plugins steal AI API keys from developers SC Staff June 17, 2026 A coordinated malware campaign on the JetBrains Marketplace has been uncovered by Aikido Security, with at least 15 plugins published under seven vendor accounts exhibiting the same malicious behavior. Supply chain NPM v12 to block supply-chain attacks with new security measures SC Staff June 10, 2026 The upcoming npm v12 will introduce stricter security protocols for the "npm install" command, a critical step in downloading and installing project dependencies. Related Events Cybercast From code to cloud: Stopping attacks in the software supply chain On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds