Attacker backdoors 116 Mastra AI npm packages via easy-day-js typosquat after maintainer phishing
An attacker abused a current maintainer's npm token, phished through a fake LinkedIn message, to plant an infostealer across Mastra's packages, the company said.
A software supply chain attack discovered on June 16, 2026, published 116 backdoored packages, almost all in the Mastra (@mastra/) namespace on npm, the registry for JavaScript and TypeScript code, after an attacker compromised the npm token of a current Mastra maintainer. Mastra is an open-source AI application framework, and it logged the incident in a public GitHub report.
The root cause was a phishing attack, not a stale account. A current, active employee was targeted through a social-engineering message from a compromised LinkedIn account that also approached maintainers of other prominent TypeScript open-source projects, Mastra said; the employee's machine was compromised, and a token tied to their npm account was used to publish the malicious releases between roughly 6:12 and 6:37 PM Pacific. Mastra said it had always required multi-factor authentication on npm but had mistakenly allowed token bypass, which it has since removed. External trackers put the combined weekly download volume of the affected packages in the low millions; Mastra's own report does not state a figure.
The attacker planted the malicious code through a dependency called easy-day-js, a typosquat of the widely used dayjs date library, added to the compromised packages. The latest version of easy-day-js carried an obfuscated postinstall dropper that downloaded and ran a second-stage payload from attacker-controlled servers. That payload deployed a cross-platform infostealer built to exfiltrate cryptocurrency wallet data, browser history and developer credentials, then self-deleted.
Mastra said it became aware of the attack at 8:45 PM Pacific, contacted npm and trusted third parties including Socket Security, and unpublished or deprecated all affected versions, publishing clean replacements by early the next morning. It advised teams using its npm packages to audit projects for the compromised easy-day-js dependency and upgrade to the clean versions.
The episode is the latest to turn a developer's trusted access into an attack path. Reporting on the full blast radius remains early; Mastra puts the number of malicious packages published at 116.
Founder and Chief Editor of Data Phoenix — a San Francisco Bay Area media and education platform focused on AI and Data.
More news

AWS releases six open-source Hugging Face deployment skills for SageMaker

Google Research releases MilleMiglia logistics benchmark generator

AWS launches AgentCore Runtime V2 with elastic memory and snapshot starts
