Malware
easy-day-js
- First Reported
- Jun 17, 2026
- Latest Reported
- Jun 17, 2026
Reported Context (1)
- unmodified code; the attack is delivered through an injected dependency, a typosquatted package named easy-day-js added to each package's dependency list. easy-day-js carries an obfuscated payload in a postinstall Malicious Dependency Compromises 141 Mastra npm Packages in Supply-Chain Campaign
MITRE ATT&CK (17)
Vendors (1)
Products (15)
Tools (1)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.