the entire @mastra npm scope got hijacked last night with 141 packages including @mastra/core
The attacker didn't touch any Mastra source code but just added one dependency to every package: easy-day-js which is a clean-looking dayjs clone. The trick was in semver that is they pinned ^1.11.21 but the latest tag pointed to 1.11.22 which had a postinstall hook. You audit 1.11.21 but npm installs 1.11.22 . full details - submitted by /u/BattleRemote3157 [link] [ ]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
