140+ npm Packages Compromised in Coordinated Supply Chain Attack
Reported 17 Jun 2026 by otx · Severity: medium
More than 140 Mastra npm packages were compromised through a supply chain attack that injected a typosquatted dependency called easy-day-js. A single npm account published malicious versions within a short timeframe, affecting packages including @mastra/core with over 918K weekly