Mastra npm Supply Chain: easy-day-js Typosquat Delivers Cross-Platform RAT to 144 Packages
How typosquatted npm packages targeting the Mastra AI agent framework infected 144 downstream enterprise packages with a cross-platform RAT.
This post is part of the Week of June 19, 2026 Security Roundup.
Overview
On June 17, 2026, an attacker compromised the @mastra npm organization and mass-published 144 backdoored package versions in an 88-minute window. Mastra is an open-source TypeScript AI agent framework with combined weekly downloads exceeding 1.1 million. The attack vector was a stale contributor account with publish access that was never revoked after the contributor left the project.
Attack Chain
Stage 1: Staleness-Based Account Compromise
The attacker hijacked the npm account ehindero — a legitimate former Mastra contributor whose scope publish permissions were never revoked. npm does not expire scope publish permissions on inactivity, meaning a single compromised stale credential was sufficient to publish to every package under the @mastra scope.
Stage 2: Trojan Dependency — easy-day-js
Rather than directly injecting malware into Mastra's source, the attacker created a dependency called easy-day-js — a typosquat of the widely-used dayjs date library. The typosquat was engineered to survive casual review:
- Duplicated dayjs's author name, homepage, repository URL, license, and version numbering verbatim
- First version (
1.11.21, published June 16 at 07:05 UTC) was a clean, functional copy of dayjs with no malicious code — establishing a credible package history - Malicious version (
1.11.22, published June 17 at 01:01 UTC) added an obfuscatedsetup.cjsdropper in thepostinstallhook
Mastra packages were updated to include "easy-day-js": "^1.11.21" — a semver range that automatically resolves to the latest matching version at install time. Once 1.11.22 was published, every fresh npm install of any affected Mastra package automatically pulled the payload.
Stage 3: Payload — Cross-Platform RAT
The postinstall dropper:
- Disables TLS certificate validation
- Downloads a second-stage Node.js payload from attacker-controlled infrastructure
- Installs OS-level login persistence (Windows startup, macOS LaunchAgent, Linux cron/systemd)
The second-stage RAT:
- Inventories 166 cryptocurrency wallet browser extensions (MetaMask, Phantom, Coinbase Wallet, etc.)
- Harvests browser history, cookies, and saved credentials from Chrome, Brave, and Edge
- Exfiltrates discovered CI/CD secrets, environment variables, and
.envfiles - Establishes persistent C2 beacon
Scope and Detection Timeline
- June 16, 07:05 UTC: Clean
[email protected]published - June 17, 01:01 UTC: Malicious
[email protected]published - June 17, 01:01–02:29 UTC (88 minutes): 144
@mastra/*package versions published with the malicious dependency - June 17, ~02:30 UTC: Detected by external security researcher (SafeDep/Orca Security); npm notified
- June 17: Malicious packages removed;
ehinderoaccount suspended; clean versions published
Remediation
# Check if any affected Mastra versions are in your lock file
# Affected: @mastra/* versions published 2026-06-17 01:01 - 02:29 UTC
# Check your package-lock.json or yarn.lock for @mastra/* versions in this window
# Update all @mastra/* packages to latest clean versions
npm update @mastra/core @mastra/client-js # (and any other @mastra/* deps)
# If your environment ran npm install during the attack window:
# 1. Treat the machine/CI runner as compromised
# 2. Rotate ALL secrets: API keys, cloud credentials, DB passwords, JWT secrets
# 3. Audit cryptocurrency wallet extensions
# 4. Scan for persistence mechanisms:
# - Windows: HKCU\Software\Microsoft\Windows\CurrentVersion\Run
# - macOS: ~/Library/LaunchAgents/*.plist
# - Linux: crontab -l; ls /etc/cron.*; systemctl list-units --user
Structural Fix: Prevent Stale Contributor Attacks
This attack is entirely preventable. Project maintainers should:
- Periodically audit npm organization members and revoke access for departed contributors
- Require SLSA-level provenance attestations for all npm publishes (
npm publish --provenance) - Pin dependencies to exact versions (
1.11.21) not ranges (^1.11.21) for critical transitive dependencies - Enable
npm audit signaturesin CI to verify package signatures