---
title: "144 Mastra npm Packages Compromised via Supply Chain Attack"
url: https://daily.dev/posts/144-mastra-npm-packages-compromised-via-supply-chain-attack-gji1xidw9
source_url: https://orca.security/resources/blog/mastra-npm-supply-chain-attack
type: article
source: "Orca Security Blog"
published: 2026-06-17T15:32:43.217Z
updated: 2026-06-17T15:34:24.081Z
tags: ["cyber", "malware", "npm"]
reading_time: 4
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# 144 Mastra npm Packages Compromised via Supply Chain Attack

**[Orca Security Blog](https://daily.dev/sources/orca-security-blog)** · 4 min read · 0 upvotes · 0 comments

## Summary

A critical supply chain attack compromised 144 npm packages under the @mastra/* scope on June 17, 2026. An attacker hijacked a contributor account and republished 142 packages with a malicious dependency — a typosquat of dayjs called 'easy-day-js' — that deployed a cross-platform infostealer via npm's postinstall hook. The malware harvests browser credentials, extracts data from 166 cryptocurrency wallet extensions, establishes cross-platform persistence, and exfiltrates data to attacker C2 infrastructure, all triggered by a simple 'npm install'. The @mastra/core package alone has ~918K weekly downloads. Any developer workstation, CI runner, or build system that installed affected packages after June 16, 2026 should be treated as fully compromised. Remediation requires rolling back packages, rotating all credentials, migrating crypto wallets, and removing persistence artifacts. Network IOCs and file system paths for detection are provided.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://orca.security/resources/blog/mastra-npm-supply-chain-attack>

## Similar posts on daily.dev

- [Over 140 popular Mastra npm Packages Hit by Supply Chain Attack](https://daily.dev/posts/over-140-popular-mastra-npm-packages-hit-by-supply-chain-attack-cci9tnher) · Aikido Security · 1 upvotes · 0 comments
- [140\+ Mastra npm Packages Compromised in Coordinated Supply C...](https://daily.dev/posts/140-mastra-npm-packages-compromised-in-coordinated-supply-c--exakcctn3) · Socket · 4 upvotes · 0 comments
- [Mastra npm Supply Chain Attack: 140\+ Packages Backdoored via easy-day-js Typosquat](https://daily.dev/posts/mastra-npm-supply-chain-attack-140-packages-backdoored-via-easy-day-js-typosquat-cj8pwowee) · StepSecurity · 24 upvotes · 2 comments
- [Mastra npm Scope Takeover](https://daily.dev/posts/mastra-npm-scope-takeover-bkpvk6ohg) · Snyk · 3 upvotes · 0 comments
- [Microsoft links Mastra AI supply chain attack to North Korean hackers](https://daily.dev/posts/microsoft-links-mastra-ai-supply-chain-attack-to-north-korean-hackers-nwwazvepp) · BleepingComputer · 0 upvotes · 0 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#malware](https://daily.dev/tags/malware), [#npm](https://daily.dev/tags/npm)

[View this post on daily.dev](https://daily.dev/posts/144-mastra-npm-packages-compromised-via-supply-chain-attack-gji1xidw9)
