A critical supply chain attack compromised 144 npm packages under the @mastra/* scope on June 17, 2026. An attacker hijacked a contributor account and republished 142 packages with a malicious dependency — a typosquat of dayjs called 'easy-day-js' — that deployed a cross-platform infostealer via npm's postinstall hook. The malware harvests browser credentials, extracts data from 166 cryptocurrency wallet extensions, establishes cross-platform persistence, and exfiltrates data to attacker C2 infrastructure, all triggered by a simple 'npm install'. The @mastra/core package alone has ~918K weekly downloads. Any developer workstation, CI runner, or build system that installed affected packages after June 16, 2026 should be treated as fully compromised. Remediation requires rolling back packages, rotating all credentials, migrating crypto wallets, and removing persistence artifacts. Network IOCs and file system paths for detection are provided.