Mastra npm packages compromised in 'easy-day-js' supply chain attack App Security
By exploiting npm’s install-time script execution, attackers gained the ability to harvest browser data from Chrome, Edge, and Brave, extract credentials from 166 cryptocurrency wallet extensions (including MetaMask, Phantom, Coinbase, and Binance), perform full host reconnaissance, establish cross-platform persistence, and exfiltrate all collected data to attacker infrastructure. A critical supply chain attack was disclosed affecting the entire @mastra/* npm scope, allowing attackers to deploy a cross-platform infostealer on any system that installed affected packages.
The Security Issue
The day before, the attacker published a clean easy-day-js@1.11.21 to establish credibility, then weaponized it as v1.11.22 minutes before the mass-publish.
Further details indicate that network IOCs to block include 23.254.164.92 and 23.254.164.123 (Hostwinds, ASN AS54290).
Because compromised packages pinned “^1.11.21”, npm’s semver resolution automatically pulled the malicious version.
The malicious dependency easy-day-js@1.11.22 is the direct vector.
Risk to Applications
A critical supply chain attack was disclosed affecting the entire @mastra/* npm scope, allowing attackers to deploy a cross-platform infostealer on any system that installed affected packages. Due to the potential for credential theft, cryptocurrency wallet compromise, and full system persistence, immediate remediation is required for all affected environments. No user interaction beyond running “npm install” is required for compromise.
Regardless of attribution, the severity and ease of exploitation make this incident high risk, especially for organizations with large JavaScript/TypeScript codebases and CI/CD pipelines that pull npm dependencies automatically.
Successful exploitation allows attackers to steal credentials and secrets, compromise cryptocurrency wallets, establish persistent access across all major operating systems, and execute arbitrary code remotely, leading to service disruption, data exposure, and potential full infrastructure compromise.
How Orca Can Help Orca enables customers to quickly identify assets running compromised @mastra/* package versions and detect the presence of the malicious easy-day-js dependency across cloud workloads, container images, and CI/CD pipelines.
Fix Recommendations
-
Network IOCs to block include 23.254.164.92 and 23.254.164.123 (Hostwinds, ASN AS54290).
-
How Orca Can Help Orca enables customers to quickly identify assets running compromised @mastra/* package versions and detect the presence of the malicious easy-day-js dependency across cloud workloads, container images, and CI/CD pipelines.
Analysis
As AI tooling proliferates, security teams face expanding attack surfaces tied to model inference and data pipelines.
Security teams should monitor vendor advisories and threat intelligence sources closely for additional context or updates. Organizations with mature security programs are advised to incorporate this intelligence into their regular risk assessments and prioritize response activities based on exposure and asset criticality. For environments where immediate remediation is not feasible, compensating controls such as network segmentation, enhanced monitoring, and access restrictions should be evaluated. Security leadership should communicate relevant details to operational teams and ensure that incident response capabilities are prepared if exploitation is observed in the wild.
Industry observers note that this type of development highlights the ongoing need for defense-in-depth strategies and proactive security posture management. Organizations that invest in regular security assessments and employee training tend to fare better when responding to emerging threats. The security community continues to share indicators and best practices to help defenders stay ahead.
Sources
SecurityXP delivers daily cybersecurity news, vulnerability analysis, data breach reports, and threat intelligence.
Security Digest
Get the latest cybersecurity news, vulnerability alerts, and threat intelligence delivered to your inbox.
Related Articles
144 Mastra npm Packages Compromised via Hijacked Contributor Account App Security
"This makes the Mastra ecosystem an exceptionally high-value target for supply chain attackers." The "easy-day-js" package launches an obfuscated payload...
Application SecuritySupply Chain Attack Hits Popular WordPress Plugins Through Awesome Motive CDN App Security
According to the company's investigation, attackers exploited a known vulnerability in a third-party plugin called UpdraftPlus running on a marketing website...
Cloud SecurityFeds & npm Issue Supply Chain Security Guidance
Faster development times, innovation, and a thriving open-source community have all been made possible by the ability to use another developer's project as a dependency. With many JavaScript projects
AI/ML SecurityOVHcloud previews AI workspace with encrypted tools AI Security
OVHcloud says OVHai Workspace includes an end-to-end encryption option covering data and communications, including within partner applications integrated...