easy-day-js: Supply Chain Campaign Targets Mastra npm Packages
2026-06-17 • Jfrog •
A malicious npm dependency, easy-day-js, was added to 143 Mastra packages as a production dependency, causing fresh installs to resolve from a clean decoy version to weaponized [email protected] through a caret version range. Its obfuscated postinstall loader disabled TLS validation, downloaded a second-stage Node.js payload from attacker infrastructure, launched it as a detached process, and deleted itself. The second stage collected host, process, browser-history, application, and wallet-extension inventory, then supported arbitrary follow-on module execution through C2 commands. JFrog also documented cross-platform persistence artifacts under Node-themed paths and advised treating affected developer or CI systems as compromised and rotating exposed credentials.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://23.254.164.123:443/4989… | 2026-06-20 | 2026-06-20 |
| URL | https://23.254.164.92:8000/upda… | 2026-06-20 | 2026-06-20 |
| IPv4 | 23.254.164.123 | 2026-06-20 | 2026-06-20 |
| IPv4 | 23.254.164.92 | 2026-06-20 | 2026-06-20 |