Lotu Radar About

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

The Hacker News Cybersecurity Score 6/10

Summary

Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases. The compromised version, @injectivelabs/sdk-ts@1.20.21, came embedded with fake telemetry functionality that exfiltrated data from cryptocurrency wallets. The version was

SecurityThreat Intel

Lotu Radar provides attributed news summaries and links to the original publisher. Full reporting and copyright remain with the source.