TechFlow News: On June 17, SlowMist reported that over 140 Mastra-related npm packages were compromised in a supply chain attack. Affected versions introduce the malicious dependency easy-day-js@1.11.22, which triggers attacker-controlled code execution during installation.
This attack may lead to persistent system compromise, browser data collection, wallet extension detection, credential theft, and exfiltration of sensitive data. SlowMist recommends treating any system where these affected versions were installed as potentially compromised—immediately remove the malicious dependency, reinstall trusted versions, isolate the host, and rotate all related credentials.




