How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

easy-day-js Targets Mastra, Dependency Attacks Grow

calendar_today June 17, 2026 person Sonatype Security Research Team domain sonatype

A supply chain attack exploited the Mastra AI framework by injecting the malicious easy-day-js package as a dependency, using postinstall scripts to download and execute remote payloads. It reflects an evolving pattern where attackers compromise trusted packages to distribute malicious dependencies rather than publishing entirely new malicious packages.

open_in_new Read original post