Mastra npm Packages Compromised: The easy-day-js Typosquat, IOCs, and First-Hour Response

2026-06-17 Kodem Security

https://www.kodemsecurity.com/resources/mastra-npm-packages-compromised-easy-day-js-supply-chain-attack-iocs-and-response-runbook

Thumbnail for Mastra npm Packages Compromised: The easy-day-js Typosquat, IOCs, and First-Hour Response

A hijacked former-contributor account republished more than 140 Mastra npm packages with a dependency on the malicious `easy-day-js` typosquat. Its install-time dropper fetched and launched a persistent cross-platform wallet stealer and RAT that collected browser and host data, targeted cryptocurrency extensions, and accepted follow-on commands from attacker infrastructure. Hosts that installed affected packages require persistence hunting, credential rotation, wallet migration, and potentially reimaging because removing the npm dependency does not terminate the detached payload.

Indicators of Compromise

Type Value First Seen Last Seen
HASH b73de25c053c3225a077738a1fcbd9c… 2026-06-17 2026-06-24
HASH ae70dd4f6bc0d1c8c2848e4e6b51934… 2026-06-17 2026-06-24
HASH b122a9873bedf145ae2a7fd024b5f30… 2026-06-17 2026-06-24
IPv4 23.254.164.123 2026-06-16 2026-06-24
IPv4 23.254.164.92 2026-06-16 2026-06-24
HASH 4a8860240e4231c3a74c81949be655a… 2026-06-17 2026-06-18
HASH 221c45a790dec2a296af57969e1165a… 2026-06-16 2026-06-18
URL https://23.254.164.92:8000/upda… 2026-06-16 2026-06-18

Related Reports

« Back