Mastra AI npm Supply Chain Attack (June 2026)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·2qURjX…Wz5gSummary
On June 17, 2026, attackers hijacked a dormant npm contributor account ('ehindero') to inject a malicious dependency ('easy-day-js') into 140+ packages across the @mastra npm scope, affecting an estimated 1.1 million+ weekly downloads. The trojanized dependency contained a multi-stage remote access trojan targeting developer credentials, LLM API keys, cloud secrets, and cryptocurrency wallet browser extensions across Windows, macOS, and Linux. Mastra and npm responded within hours by revoking the compromised account, unpublishing malicious versions, and forward-rolling clean releases.
Connected Entities
1 entityNo connected entities recorded yet — this investigation is not currently linked to any other page in the index.
Community submissions
- Under reviewincriminatingWayback pending6/19/2026, 10:09:51 PM
“New technical analysis published June 17-18, 2026 confirms the easy-day-js typosquat dropper deployed against 144 Mastra npm packages installs a cross-platform RAT that specifically enumerates and targets 166 cryptocurrency wallet browser extensions, harvests Chrome/Brave/Edge browser history, and opens a persistent remote command execution channel. Combined exposure exceeds 1.1 million weekly downloads; @mastra/core alone accounts for roughly 4 million monthly.”
— avoid-scout
Timeline(9 events)
2024
npm account 'ehindero' published legitimate alpha versions of @mastra/core, acquiring org-wide scope publish rights that were never subsequently revoked.
Snyk16 June 2026
Account 'sergey2016' published 'easy-day-js@1.11.21' to npm — a clean, byte-identical copy of the legitimate dayjs library, seeding the attack infrastructure without triggering alerts.
StepSecurity17 June 2026
At 01:01 UTC, 'easy-day-js@1.11.22' was published with an obfuscated postinstall dropper ('setup.cjs') and tagged as 'latest', arming the previously clean package.
StepSecurity / Endor Labs17 June 2026
Between 01:12 and 02:39 UTC, hijacked account 'ehindero' executed an automated 88-minute campaign republishing 140+ @mastra/* packages each injected with the 'easy-day-js' dependency, exposing a combined 1.1 million+ weekly downloads.
StepSecurity / Snyk / Endor Labs17 June 2026
Endor Labs detected the first malicious republish approximately 2 minutes and 18 seconds after it appeared on the npm registry.
Endor Labs17 June 2026
Microsoft Defender Security Research Team published a blog post detailing the attack mechanics and threat hunting guidance.
Microsoft Security Blog17 June 2026
npm removed the 'easy-day-js' package from the registry and flagged malicious versions under advisory SNYK-JS-EASYDAYJS-17353313. The 'ehindero' account was removed as scope owner.
Snyk17 June 2026
Mastra forward-rolled 142 packages to clean versions, moved the 'latest' dist-tag past all compromised releases, restoring @mastra/core latest to version 1.42.0, and disabled token bypass authentication on all packages.
Snyk / The Hacker News18 June 2026
Multiple security firms including OX Security, Orca Security, Phoenix Security, SafeDep, Cloudsmith, and Kodem published detailed technical analyses and incident response runbooks.
OX SecurityDecision Log
- hash: 6FEpP5vh3Xym71jYs44mRjq7Pdird7XVgcjRuNPRkbZ1
- hash: J9yHSmEs27ubbsWJUQEddPWFsJotJGX4vQ1Ud8Kw3DJ7
- hash: GDUcSUD2NG6q8Kh9tmF9bqZfSfpUfryH7K8b5Lt7U69j
This investigation is cryptographically anchored to the Solana blockchain (3 events). 11 of 12 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 6/19/2026, 12:20:56 PM
last updated: 8/25/2026, 10:39:18 PM
5 viewsavoid.net — verified advice for a post-truth world