easy-day-js: how 140+ npm packages were trojanised from a forgotten maintainer account
On 17 June 2026 an attacker pushed more than 140 @mastra npm packages carrying a malicious dependency that runs a trojan during postinstall. What happened, and how to defend against it.
By Irene Ocando · Directora de Cumplimiento Normativo Hard2bit