As many as 145 npm packages associated with the Mastra
namespace ("@mastra/*"), a popular open-source JavaScript and
TypeScript framework for building artificial intelligence (AI)
applications, have been compromised as part of a software supply
chain attack codenamed easy-day-js, per findings from Endor Labs,
JFrog, OX Security, SafeDep, Socket, StepSecurity, and Synk. "A
single npm account (
Read more https://thehackernews.com/2026/06/144-mastra-npm-packages-compromised-via.html

