140+ npm Packages Compromised in Coordinated Supply Chain Attack
June 17, 2026, 8:24 p.m.
Description
More than 140 Mastra npm packages were compromised through a supply chain attack that injected a typosquatted dependency called easy-day-js. A single npm account published malicious versions within a short timeframe, affecting packages including @mastra/core with over 918K weekly downloads. The attack executes during npm install via a postinstall hook, deploying a two-stage payload. The first stage disables TLS validation and downloads a second-stage implant that installs cross-platform persistence on Windows, macOS, and Linux. This implant functions as a command-and-control client that steals cryptocurrency wallet inventories from 166+ browser extensions, harvests browser history, and can execute arbitrary code sent by operators. The malicious code executes before developers import packages, compromising systems during installation.
Tags
Date
- Created: June 17, 2026, 1:38 p.m.
- Published: June 17, 2026, 1:38 p.m.
- Modified: June 17, 2026, 8:24 p.m.
Indicators
- b122a9873bedf145ae2a7fd024b5f309007dbb025149f4dc4ac3f7e4f32a36a4
- c38954e85bf5433e61e7c8f4230336695624ae88b6953afabf7bf817aa91b638
- 221c45a790dec2a296af57969e1165a16f8f49733aeab64c0bbd768d9943badf
- cdec8b20338beb708b5be8d3d7a3041a35a8b0fb92f9186262f312d55ff82066
- 9570f77a5e1511869f4e554e7166df9fde081f2583e293c2569621792ed7d9c9
- https://23.254.164.92:8000/update/49890878'
- https://23.254.164.92:8000/update/49890878
Additional Informations
- Technology
- hwsrv-1327785.hostwindsdns.com
- hwsrv-1327786.hostwindsdns.com