Mastra npm packages added easy-day-js malware, exposing developer systems and CI runners to infostealer risks.
You might want to check out XO, which includes this plugin. Most rules target JavaScript and TypeScript, but some also lint CSS, HTML, JSON, and Markdown when used ...