140+ npm Packages Compromised in Coordinated Supply Chain Attack

June 17, 2026, 8:24 p.m.

Description

More than 140 Mastra npm packages were compromised through a supply chain attack that injected a typosquatted dependency called easy-day-js. A single npm account published malicious versions within a short timeframe, affecting packages including @mastra/core with over 918K weekly downloads. The attack executes during npm install via a postinstall hook, deploying a two-stage payload. The first stage disables TLS validation and downloads a second-stage implant that installs cross-platform persistence on Windows, macOS, and Linux. This implant functions as a command-and-control client that steals cryptocurrency wallet inventories from 166+ browser extensions, harvests browser history, and can execute arbitrary code sent by operators. The malicious code executes before developers import packages, compromising systems during installation.

Date

  • Created: June 17, 2026, 1:38 p.m.
  • Published: June 17, 2026, 1:38 p.m.
  • Modified: June 17, 2026, 8:24 p.m.

Indicators

  • b122a9873bedf145ae2a7fd024b5f309007dbb025149f4dc4ac3f7e4f32a36a4
  • c38954e85bf5433e61e7c8f4230336695624ae88b6953afabf7bf817aa91b638
  • 221c45a790dec2a296af57969e1165a16f8f49733aeab64c0bbd768d9943badf
  • cdec8b20338beb708b5be8d3d7a3041a35a8b0fb92f9186262f312d55ff82066
  • 9570f77a5e1511869f4e554e7166df9fde081f2583e293c2569621792ed7d9c9
  • https://23.254.164.92:8000/update/49890878'
  • https://23.254.164.92:8000/update/49890878

Additional Informations

  • Technology
  • hwsrv-1327785.hostwindsdns.com
  • hwsrv-1327786.hostwindsdns.com