140+ npm Packages Compromised in Coordinated Supply Chain Attack

Reported 17 Jun 2026 by otx · Severity: medium

More than 140 Mastra npm packages were compromised through a supply chain attack that injected a typosquatted dependency called easy-day-js. A single npm account published malicious versions within a short timeframe, affecting packages including @mastra/core with over 918K weekly