<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>cybercrime.club</title><link>https://cybercrime.club/tags/easy-day-js/</link><description>Infrastructure security news for people who build infrastructure.</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Wed, 17 Jun 2026 23:12:25 -0400</lastBuildDate><atom:link href="https://cybercrime.club/tags/easy-day-js/" rel="self" type="application/rss+xml"/><item><title>Mastra npm Scope Hijacked: 144 AI-Framework Packages Backdoored with the easy-day-js Stealer</title><link>https://cybercrime.club/posts/mastra-npm-easy-day-js-144-packages-scope-takeover/</link><pubDate>Wed, 17 Jun 2026 23:12:25 -0400</pubDate><guid>https://cybercrime.club/posts/mastra-npm-easy-day-js-144-packages-scope-takeover/</guid><description>An attacker hijacked a former contributor's npm account to republish ~144 @mastra packages — including @mastra/core (918K weekly downloads) — each pulling in easy-day-js, a dayjs typosquat that drops a cross-platform crypto/infostealer at install time.</description><category>supply-chain</category></item></channel></rss>