A supply chain attack exploited the Mastra AI framework by injecting the malicious easy-day-js package as a dependency, using postinstall scripts to download and execute remote payloads. It reflects an evolving pattern where attackers compromise trusted packages to distribute malicious dependencies rather than publishing entirely new malicious packages.