What happened
Sapphire Sleet hijacked a forgotten contributor account with @mastra npm scope publish access. Over 88 minutes, 142 packages were republished with the easy-day-js RAT injected. Clean v1 built false trust before RAT payload was revealed in later versions.