easy-day-js / Mastra npm Supply Chain Attack
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·HmGSnn…hQZqSummary
On June 16–17, 2026, attackers published a typosquatted npm package named easy-day-js mimicking the legitimate dayjs date library, then used a hijacked former-contributor npm account (ehindero) to inject it as a dependency across 141–144 packages in the @mastra organization within an 88-minute window. The malicious postinstall payload functioned as a cross-platform remote access trojan (RAT) and infostealer, exfiltrating cryptocurrency wallet credentials, browser history, and developer secrets before self-deleting, with affected packages carrying a combined weekly download count exceeding 1.1 million.
Connected Entities
1 entityNo connected entities recorded yet — this investigation is not currently linked to any other page in the index.
Timeline(8 events)
29 May 2026
An identical loader to the easy-day-js dropper was detected on public malware sandboxes, approximately 19 days before the Mastra attack, indicating prior toolkit testing or use.
JFrog Security Research16 June 2026
npm account sergey2016 published easy-day-js@1.11.21 at 07:05 UTC — a clean, fully functional copy of the legitimate dayjs library with no malicious code, establishing a credible package history.
StepSecurity / JFrog17 June 2026
easy-day-js@1.11.22 published at 01:01 UTC by sergey2016 with obfuscated malicious postinstall dropper (setup.cjs). TLS verification disabled; C2 download from 23.254.164.92:8000.
StepSecurity / Socket17 June 2026
Beginning at 01:12 UTC, compromised ehindero account mass-published 141–144 trojanized @mastra packages over 88 minutes (through approximately 02:39 UTC), each listing easy-day-js@^1.11.21 as a dependency.
Socket / StepSecurity17 June 2026
Mastra team became aware of the attack at approximately 8:45 PM PT (June 16 US time) and contacted npm and Socket Security. Began unpublishing compromised packages.
Mastra GitHub Issue #1806117 June 2026
By 11:57 PM PT: 110 malicious packages unpublished; 6 packages deprecated (npm prevented full unpublishing). Safe versions published via PR #18056 around 1:00 AM PT. MFA token bypass vulnerability removed.
Mastra GitHub Issue #1806117 June 2026
Compromised maintainer confirmed as an active Mastra employee whose account was hijacked via social phishing through a fraudulent LinkedIn message. Attacker had changed the ehindero account email to ehindero2016@tutamail.com.
Mastra GitHub Issue #18061 / Snyk17 June 2026
Multiple security firms (StepSecurity, Socket, OX Security, JFrog, Snyk, Phoenix Security) published public technical analyses of the attack. JFrog flagged all compromised versions within 24 hours of detection.
Multiple security research firmsDecision Log
- hash: EQ3Wx6xGDUJsQstGtUCpFDHnvooVLGoDhE3T6iv32fLx
This investigation is cryptographically anchored to the Solana blockchain (1 event). 10 of 10 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 6/17/2026, 5:03:53 PM
last updated: 7/27/2026, 1:22:49 PM
3 viewsavoid.net — verified advice for a post-truth world