Attacker backdoors 116 Mastra AI npm packages via easy-day-js typosquat after maintainer phishing
An attacker abused a current maintainer's npm token, phished through a fake LinkedIn message, to plant an infostealer across Mastra's packages, the company said.
A software supply chain attack discovered on June 16, 2026, published 116 backdoored packages, almost all in the Mastra (@mastra/) namespace on npm, the registry for JavaScript and TypeScript code, after an attacker compromised the npm token of a current Mastra maintainer. Mastra is an open-source AI application framework, and it logged the incident in a public GitHub report.
The root cause was a phishing attack, not a stale account. A current, active employee was targeted through a social-engineering message from a compromised LinkedIn account that also approached maintainers of other prominent TypeScript open-source projects, Mastra said; the employee's machine was compromised, and a token tied to their npm account was used to publish the malicious releases between roughly 6:12 and 6:37 PM Pacific. Mastra said it had always required multi-factor authentication on npm but had mistakenly allowed token bypass, which it has since removed. External trackers put the combined weekly download volume of the affected packages in the low millions; Mastra's own report does not state a figure.
The attacker planted the malicious code through a dependency called easy-day-js, a typosquat of the widely used dayjs date library, added to the compromised packages. The latest version of easy-day-js carried an obfuscated postinstall dropper that downloaded and ran a second-stage payload from attacker-controlled servers. That payload deployed a cross-platform infostealer built to exfiltrate cryptocurrency wallet data, browser history and developer credentials, then self-deleted.
Mastra said it became aware of the attack at 8:45 PM Pacific, contacted npm and trusted third parties including Socket Security, and unpublished or deprecated all affected versions, publishing clean replacements by early the next morning. It advised teams using its npm packages to audit projects for the compromised easy-day-js dependency and upgrade to the clean versions.
The episode is the latest to turn a developer's trusted access into an attack path. Reporting on the full blast radius remains early; Mastra puts the number of malicious packages published at 116.
An entrepreneur with over a decade of experience in AI, Cloud, and HPC. He is currently a DevOps Architect and the founder of Data Phoenix, an influential media voice for the AI industry, with a strong focus on community building and open source.
More news

Study: Some personal AI agents steer wealthier personas toward pricier options

Databricks adds Workday Data Connect federation to Unity Catalog

Google Cloud introduces a universal Gemini agent for enterprise work
