Malicious Dependency Compromises 141 Mastra npm Packages in Supply-Chain Campaign

Summary
A malicious dependency added to 141 Mastra npm packages ran an install-time loader that deployed a cross-platform implant. Socket says the payload collected browser history and wallet-extension inventories, installed persistence, and enabled further remote tasking.
Key points
- A single npm account published 141 malicious @mastra/* package versions on June 17, 2026; the packages added the typosquatted dependency easy-day-js.
- The dependency's postinstall hook ran during npm install, before the Mastra package was imported or used, and downloaded a second-stage payload.
- The cross-platform implant installs login persistence on Windows, macOS, and Linux and can receive and execute follow-on code from its operators.
- The recovered sample collected browser history and inventoried installed cryptocurrency wallet extensions; Socket says it did not copy wallet-extension data or read saved passwords and cookies.
- Treat machines and CI runners that installed affected versions as potentially compromised; the article recommends containment, persistence removal, clean rebuilds, and rotating exposed credentials.
- Socket says it detected easy-day-js within six minutes and automatically flagged and blocked affected installs for its customers.
Article Details
- Attack Vectors
- A human npm account mass-published compromised Mastra releases containing an added easy-day-js dependency; the original package code remained unchanged.
- A clean initial release established benign package history before a subsequent release introduced a malicious postinstall hook. Transitive dependency installation triggered execution before application imports.
- The obfuscated loader disabled TLS certificate validation, downloaded a second-stage payload, launched it as a detached background process, and deleted itself.
- The second-stage implant established login persistence and polled its operators for arbitrary follow-on code through Node and Shell runners.
- The recovered second stage collected browser history, cryptocurrency wallet-extension inventory, and host reconnaissance data for exfiltration. Although the introduction describes wallet stored-data theft, the detailed analysis explicitly states that this sample did not read wallet LevelDB contents, saved passwords, or cookies.
- Defensive Notes
- Treat developer workstations, CI runners, and build environments that installed affected versions as potentially compromised, even if applications never imported the packages.
- Search repositories, lockfiles, package-manager metadata, CI logs, build artifacts, SBOMs, and package caches for affected versions and the injected dependency. Use npm ls easy-day-js as an initial check.
- Isolate affected workstations and preserve logs before remediation. Suspend affected CI workflows and review releases, container images, packages, and deployment artifacts produced after installation.
- Remove affected versions and dependency-lock entries, delete node_modules, clear package caches, and rebuild in clean environments. Verify metadata and provenance before selecting a known-clean prior release.
- Package removal alone is insufficient. Remove the Windows Run-key value, macOS LaunchAgent, or Linux systemd user unit, along with dropped payloads, configuration files, temporary loader artifacts, and browser-history copies.
- Hunt for detached node processes running the dropped payload and unexpected outbound connections during dependency installation.
- Precautionarily rotate npm tokens, GitHub tokens, cloud credentials, CI/CD secrets, and SSH/Git credentials exposed to the installation context. The recovered sample did not read saved passwords or cookies, but follow-on tasking could deliver additional collection code.
- For high-value wallets present on affected machines, the source recommends moving funds to a new wallet generated from a fresh seed phrase on a clean device; password rotation alone is insufficient.
- Disable lifecycle scripts by default with npm install --ignore-scripts and selectively allow necessary scripts. Apply dependency allowlisting, package cooldown periods, lockfile enforcement, SBOM generation, and network egress controls.
- Do not rely solely on provenance or trusted publishing: the malicious releases used an account with legitimate publishing rights. Socket reports that its customers' affected installations were flagged and blocked before the malicious hook executed.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| HOSTNAME | hwsrv-1327785[.]hostwindsdns[.]com | Threat-infrastructure hostname explicitly listed among the attack's network indicators. |
| HOSTNAME | hwsrv-1327786[.]hostwindsdns[.]com | Threat-infrastructure hostname explicitly listed among the attack's network indicators. |
| IPV4 | 23[.]254[.]164[.]123 | Operator command-and-control and exfiltration address listed in the network indicators. |
| IPV4 | 23[.]254[.]164[.]92 | Stage-two delivery infrastructure listed in the network indicators. |
| SHA256 | 221c45a790dec2a296af57969e1165a16f8f49733aeab64c0bbd768d9943badf | Hash of the recovered stage-two stealer. |
| SHA256 | 9570f77a5e1511869f4e554e7166df9fde081f2583e293c2569621792ed7d9c9 | Hash of a loader variant listed by the source. |
| SHA256 | b122a9873bedf145ae2a7fd024b5f309007dbb025149f4dc4ac3f7e4f32a36a4 | Hash of easy-day-js setup.cjs, the stage-one loader. |
| SHA256 | c38954e85bf5433e61e7c8f4230336695624ae88b6953afabf7bf817aa91b638 | Hash of the malicious easy-day-js@1.11.22 package.json. |
| SHA256 | cdec8b20338beb708b5be8d3d7a3041a35a8b0fb92f9186262f312d55ff82066 | Hash of a loader variant listed by the source. |
| URL | hxxps[:]//23[.]254[.]164[.]123/49890878 | Second-stage command-and-control and exfiltration endpoint listed in the network indicators. |
| URL | hxxps[:]//23[.]254[.]164[.]92:8000/update/49890878 | Stage-two payload download URL listed in the network indicators. |
MITRE ATT&CK
T1027 · Obfuscated Files or Informationsetup.cjs used obfuscator.io string arrays, a custom-base64 decoder, and array rotation to conceal the downloader.T1033 · System Owner/User DiscoveryHost reconnaissance collected the user ID.T1036 · MasqueradingPayload directories, persistence entries, and service descriptions imitated Node/NVM tooling or a system configuration service.T1041 · Exfiltration Over C2 ChannelCollected browser history, wallet-extension inventory, and host data were exfiltrated through the operators' C2 channel.T1057 · Process DiscoveryThe recovered implant enumerated running processes.T1059.001 · PowerShellThe Windows Run-key persistence mechanism invoked hidden PowerShell.T1059.007 · JavaScriptThe postinstall hook executed setup.cjs with Node.js, and the implant supported a Node runner for operator-supplied code.T1070.004 · File DeletionThe loader deleted its own script after launching the second stage to limit forensic traces.T1071.001 · Web ProtocolsThe implant used HTTPS POST for custom ICAP-style tasking and exfiltration, including repeated Check polling.T1082 · System Information DiscoveryHost reconnaissance collected hostname, architecture, and platform information.T1105 · Ingress Tool TransferThe loader fetched the second-stage JavaScript payload from an attacker-controlled HTTPS endpoint and wrote it to a temporary file.T1195.001 · Compromise Software Dependencies and Development ToolsCompromised Mastra package manifests introduced a malicious transitive dependency that executed during npm installation.T1217 · Browser Information DiscoveryThe payload copied Chrome, Edge, and Brave profile History databases to temporary directories and read them with node:sqlite.T1518 · Software DiscoveryThe implant enumerated installed applications and matched browser-extension directories against a hardcoded list of 166 wallet-extension IDs.T1543.001 · Launch AgentmacOS persistence used a user LaunchAgent plist with RunAtLoad enabled.T1543.002 · Systemd ServiceLinux persistence used a systemd user unit whose ExecStart launched the dropped payload.T1547.001 · Registry Run Keys / Startup FolderWindows persistence used the NvmProtocal value under the current user's CurrentVersion\Run key.
Malware
Vendors
Products
@mastra/coreThe affected packages include @mastra/core, which receives more than 918K weekly npm downloads, giving this campaign a large potential blast radius. Because the payload executes during installation, systems may beBinance Walletit carries a hardcoded list of 166 wallet browser-extension IDs (MetaMask, Phantom, Coinbase Wallet, Binance Wallet, TronLink, and others), lists each browser profile's Local Extension Settings directory, matches theBraveBrowser history: from Chrome, Edge, and Brave: it copies each profile's History database to a temp browser-hist-… directory and reads it via Node's built-in node:sqlite. (The recovered payload accesses History only).Coinbase Walletinventory: it carries a hardcoded list of 166 wallet browser-extension IDs (MetaMask, Phantom, Coinbase Wallet, Binance Wallet, TronLink, and others), lists each browser profile's Local Extension SettingsEdgeBrowser history: from Chrome, Edge, and Brave: it copies each profile's History database to a temp browser-hist-… directory and reads it via Node's built-in node:sqlite. (The recovered payload accesses History only).Google ChromeBrowser history: from Chrome, Edge, and Brave: it copies each profile's History database to a temp browser-hist-… directory and reads it via Node's built-in node:sqlite. (The recovered payload accesses History only).Linuxof over 160 cryptocurrency wallet browser extensions, and installs persistence across Windows, macOS, and Linux before exfiltrating to the operators' C2 servers.macOSdata of over 160 cryptocurrency wallet browser extensions, and installs persistence across Windows, macOS, and Linux before exfiltrating to the operators' C2 servers.MastraSocket has detected a malicious npm supply chain campaign involving compromised @mastra/* packages published under the Mastra namespace. A single npm account (ehindero) mass-published more than 140 malicious packagesMetaMaskCryptocurrency wallet inventory: it carries a hardcoded list of 166 wallet browser-extension IDs (MetaMask, Phantom, Coinbase Wallet, Binance Wallet, TronLink, and others), lists each browser profile's Local ExtensionMicrosoft Windowsthe stored data of over 160 cryptocurrency wallet browser extensions, and installs persistence across Windows, macOS, and Linux before exfiltrating to the operators' C2 servers.Node.jsThe second stage payload is a ~41 KB cross-platform Node.js tasking client, not a fire-and-forget stealer: it installs login persistence, then beacons to the operator and runs whatever follow-on code is returned.npmSocket has detected a malicious npm supply chain campaign involving compromised @mastra/* packages published under the Mastra namespace. A single npm account (ehindero) mass-published more than 140 malicious packagesPhantomwallet inventory: it carries a hardcoded list of 166 wallet browser-extension IDs (MetaMask, Phantom, Coinbase Wallet, Binance Wallet, TronLink, and others), lists each browser profile's Local ExtensionTronLinkhardcoded list of 166 wallet browser-extension IDs (MetaMask, Phantom, Coinbase Wallet, Binance Wallet, TronLink, and others), lists each browser profile's Local Extension Settings directory, matches the installed