easy-day-js is a malicious npm package that cloned the legitimate 'dayjs' date library. Published by user 'sergey2016', it initially appeared clean but later introduced an obfuscated payload via a postinstall hook. The payload acted as a dropper, downloading a cross-platform cryptocurrency-stealing trojan from attacker-controlled infrastructure, capable of harvesting browser history, stealing wallet data, and establishing persistence.