Over 140 @mastra packages were compromised through a typosquatted dependency (easy-day-js) delivering a two-stage infostealer. The loader disabled TLS validation and executed an obfuscated second stage that installed cross-platform persistence, harvested cryptocurrency wallet extensions and browser history, and established C2 via blockchain-based command infrastructure.