Blogs by Kodem Security Research Team

Mastra npm Packages Compromised: easy-day-js Supply Chain Attack
On June 17, 2026, a hijacked contributor account republished more than 140 @mastra npm packages with a malicious easy-day-js dropper that delivers a crypto-stealer and RAT. Get the IOCs, timeline, and first-hour runbook.


