Easy-day-js Mastra package-publishing campaign
Campaign
Summary
Hide ▲
Show ▼
The easy-day-js campaign mass-published more than 140 malicious npm packages across the @mastra/* namespace, creating broad supply-chain exposure for developers and build systems. The operation used the ehindero npm account in a short publishing burst on 2026-06-17. The malicious packages could reach users through normal installs before defenders removed the tainted versions.
Related Happenings
AsyncAPI repositories and npm publishing workflow hit by network compromise
Incident
H score27
First: 15.07.2026 12:16
Last: 15.07.2026 12:16
Sources 1
About this happening:
The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...
AsyncAPI repositories and npm publishing workflow hit by network compromise
IncidentAbout this happening: The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...
Jscrambler hit by network compromise
Incident
H score15
First: 13.07.2026 22:44
Last: 13.07.2026 22:44
Sources 1
About this happening:
The Jscrambler npm package suffered an unauthorized publication of a malicious version that exposed developers to infostealer theft risk. The bad release stayed li...
Jscrambler hit by network compromise
IncidentAbout this happening: The Jscrambler npm package suffered an unauthorized publication of a malicious version that exposed developers to infostealer theft risk. The bad release stayed li...
@Injectivelabs/[email protected] wallet-stealing package
Malware Activity
H score30
First: 10.07.2026 20:29
Last: 10.07.2026 20:29
Sources 1
About this happening:
The malicious @injectivelabs/[email protected] package is a wallet-stealing malware activity that can expose private keys and mnemonic seed phrases when library functions...
@Injectivelabs/[email protected] wallet-stealing package
Malware ActivityAbout this happening: The malicious @injectivelabs/[email protected] package is a wallet-stealing malware activity that can expose private keys and mnemonic seed phrases when library functions...
Injective Labs SDK project GitHub repository hit by network compromise
Incident
H score21
First: 09.07.2026 23:10
Last: 09.07.2026 23:10
Sources 1
About this happening:
The Injective Labs SDK project suffered a GitHub repository compromise that let attackers publish a malicious @injectivelabs/sdk-ts v1.20.21 package, putting developer...
Injective Labs SDK project GitHub repository hit by network compromise
IncidentAbout this happening: The Injective Labs SDK project suffered a GitHub repository compromise that let attackers publish a malicious @injectivelabs/sdk-ts v1.20.21 package, putting developer...
GitHub npm version 12 hardens installs and token management
Security Tool/Service
H score11
First: 09.07.2026 19:49
Last: 09.07.2026 19:49
Sources 1
About this happening:
GitHub released npm version 12, making install-time scripts opt-in by default and tightening package publishing controls to reduce supply-chain risk. The update al...
GitHub npm version 12 hardens installs and token management
Security Tool/ServiceAbout this happening: GitHub released npm version 12, making install-time scripts opt-in by default and tightening package publishing controls to reduce supply-chain risk. The update al...
Timeline
-
17.06.2026 10:38 2 articles · 28d ago
Easy-day-js Mastra package-publishing campaign
Initial DisclosureOn 2026-06-17, the ehindero account began mass-publishing malicious packages across the @mastra/* namespace. The short-window release burst seeded the easy-day-js supply-chain operation before the malicious versions were pulled.
Show sources
- 144 Mastra npm Packages Compromised via Hijacked Contributor Account — thehackernews.com — 17.06.2026 10:38
- 144 Mastra npm Packages Compromised via Hijacked Contributor Account — thehackernews.com — 17.06.2026 10:38