SlowMist: Over 140 Mastra npm packages suffer from supply chain attacks, posing security risks
Foresight News reports, according to SlowMist monitoring, a coordinated supply chain attack targeting more than 140 npm packages is underway. The affected packages automatically add a dependency on easy-day-js@^1.11.21 during installation, which resolves to the malicious version easy-day-js@1.11.22. This triggers attacker-controlled code via installation hooks.
Potential attacker behaviors include: executing code upon installation, maintaining persistence on Windows/macOS/Linux, collecting browser history, inventorying cryptocurrency wallet extensions, exposing credentials or CI keys through subsequent operations, and leaking data.
For any systems that have installed affected versions, consider them as potentially compromised: remove the malicious version and easy-day-js, delete node_modules and package caches, reinstall known clean versions (using verified lock files), isolate affected hosts, preserve logs, remove persistence traces, and rotate npm, GitHub, cloud service, SSH/Git, CI/CD, and wallet-related credentials if exposure is possible.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
USD/CHF Price Forecast: Shooting star warns bulls below 0.8200
Sysco Planning $1 Billion Share Offering
Matrix Service CFO Andrew J. Smith files initial beneficial ownership statement
Copasa MG declares R$ 0.26 dividend per share for 3Q 2026
