logo

easy-day-js Targets Mastra, Dependency Attacks Grow

ID: b8c6f986-9eeb-57ee-b672-69c79252351a

STIX ID: report--b8c6f986-9eeb-57ee-b672-69c79252351a

Feed Name: Security Boulevard

Threat Score
80/100

Date Published: 2026-06-17

Date Updated: 2026-06-18

Author: Sonatype Security Research Team

...
...

Security researchers identified a supply-chain campaign (tracked by Sonatype) in which attackers compromised part of the Mastra npm publishing workflow and added a malicious dependency, easy-day-js, to many Mastra packages; the package’s postinstall script attempted to download and execute a second-stage payload, potentially compromising developer workstations, CI/build agents, and production-adjacent environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.