easy-day-js is a malicious npm package masquerading as the legitimate dayjs JavaScript date library. It was used in the June 2026 compromise of more than 140 Mastra ecosystem packages after attackers abused a maintainer account and inserted the typosquatted dependency with a version range that resolved to a weaponized release. Installation of an affected package automatically invoked an obfuscated postinstall dropper, including on developer workstations and CI/CD systems before application code was imported or executed.
The dropper disabled Node.js TLS certificate validation, retrieved a second-stage cross-platform Node.js implant, launched it as a detached hidden process, and removed itself. The implant targeted Windows, macOS, and Linux, established persistence while masquerading as Node.js or NVM-related components, collected host and process information, browser history, installed-application data, and inventories of cryptocurrency-wallet browser extensions. It communicated with command-and-control infrastructure, supported arbitrary follow-on code execution, and on Windows supported reflective .NET in-memory execution and process injection. The activity was attributed by Microsoft to Sapphire Sleet, a financially motivated North Korean threat actor also known as BlueNoroff, CageyChameleon, Copernicium, and Stardust Chollima.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
During a 45-minute window, the hackers published 141 packages that contained the malicious dependency easy-day-js, a typosquat of the legitimate dayjs date library... An obfuscated postinstall dropper in the dependency would fetch a second-stage payload from the attackers’ servers, write it to the temp directory, execute it as a detached, hidden background process, and then delete itself to hide its tracks.
The only change was a single new dependency added to each package: easy-day-js, a clone of dayjs that downloads and runs a cryptocurrency-stealing remote access trojan when you install it.
The campaign ... exploited a typosquatting dependency to deliver multi-stage malware ... the only change was a single injected dependency in each manifest: "easy-day-js": "^1.11.21" ... Version 1.11.22, however, added a weaponized postinstall hook running node setup.cjs, executing the malicious payload automatically during npm install.
The campaign ... exploited a typosquatting dependency to deliver multi-stage malware ... the only change was a single injected dependency in each manifest: "easy-day-js": "^1.11.21" ... Version 1.11.22, however, added a weaponized postinstall hook running node setup.cjs, executing the malicious payload automatically during npm install.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
APT38 (Sapphire Sleet) compromised the Mastra npm supply chain to inject the “easy-day-js” dependency into more than 140 npm packages
The source of the compromise was the takeover of a npm maintainer account, which had its publishing privileges abused to publish poisoned instances of Mastra code with easy-day-js, a malicious dependency.
Attackers hide malicious code in npm packages, transitive dependencies, Git repositories, or remotely hosted dependency artifacts that npm resolves during installation. | “Rather than placing malicious code directly in the package that developers install, attackers can introduce it through indirect dependencies that are automatically resolved as part of the dependency graph.”
An obfuscated postinstall dropper in the dependency would fetch a second-stage payload from the attackers’ servers, write it to the temp directory, execute it as a detached, hidden background process, and then delete itself to hide its tracks.
The malicious easy-day-js package executed an obfuscated payload during a post-install hook... The attack utilized multiple stealth techniques, including obfuscated post-install loaders...
Targeting Windows, macOS, and Linux, the malware was designed to masquerade as node-related tools while collecting system information and targeting more than 160 cryptocurrency-related browser extensions.
The attacker published “easy-day-js@1.11.21, a typosquatting clean copy of the legitimate dayjs date library.”
24 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malicious NPM dependency used in the Mastra supply chain attack. It acted as an obfuscated postinstall dropper that fetched and executed a second-stage payload, enabling compromise of developer workstations and CI/CD pipelines.
A malicious typosquatted npm package used in the Mastra supply chain compromise. It executed a postinstall payload during installation, fetched a second-stage payload, used obfuscation and self-deletion to evade detection, and ultimately deployed a stealer targeting API tokens, developer secrets, and credentials.
A typosquatted dayjs package whose malicious version used a postinstall script to steal credentials from developer workstations and CI/CD environments, then leverage compromised access to publish further malicious packages.
A malicious npm typosquat of the legitimate dayjs library used in a supply-chain attack. Its weaponized version executes a postinstall dropper that disables TLS verification, contacts C2 infrastructure, downloads and launches a second-stage Node.js implant, establishes persistence across Windows/macOS/Linux, performs reconnaissance and data theft, and self-deletes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.