easy-day-js: Supply Chain Campaign Targets Mastra npm Packages

2026-06-17 Jfrog

https://research.jfrog.com/post/easy-day-js/

Thumbnail for easy-day-js: Supply Chain Campaign Targets Mastra npm Packages

A malicious npm dependency, easy-day-js, was added to 143 Mastra packages as a production dependency, causing fresh installs to resolve from a clean decoy version to weaponized [email protected] through a caret version range. Its obfuscated postinstall loader disabled TLS validation, downloaded a second-stage Node.js payload from attacker infrastructure, launched it as a detached process, and deleted itself. The second stage collected host, process, browser-history, application, and wallet-extension inventory, then supported arbitrary follow-on module execution through C2 commands. JFrog also documented cross-platform persistence artifacts under Node-themed paths and advised treating affected developer or CI systems as compromised and rotating exposed credentials.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://23.254.164.123:443/4989… 2026-06-20 2026-06-20
URL https://23.254.164.92:8000/upda… 2026-06-20 2026-06-20
IPv4 23.254.164.123 2026-06-20 2026-06-20
IPv4 23.254.164.92 2026-06-20 2026-06-20

Related Reports

« Back