An attacker republished over 140 packages in the @mastra npm scope with a malicious dependency called easy-day-js, so installing any affected @mastra package resolves and runs a dropper that downloads malware targeting environment secrets and cryptocurrency wallets. The affected packages had millions of downloads.