CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Injective SDK on npm infected with cryptocurrency wallet stealer

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2279

As cited

Copy frozen at (site build).

threat intel

Injective SDK on npm infected with cryptocurrency wallet stealer

Hackers compromised the Injective Labs SDK repository on GitHub and published a malicious package to npm that targeted cryptocurrency wallet credentials, specifically private keys and mnemonic seed phrases. The attack exploited the trust developers place in open-source dependencies to distribute wallet-stealing malware.

Why it matters: Developers using the compromised Injective SDK package face immediate risk of cryptocurrency wallet theft; practitioners should audit npm dependencies and check for the malicious package version in their supply chains.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Injective SDK on npm infected with cryptocurrency wallet stealer

Hackers compromised the Injective Labs SDK repository on GitHub and published a malicious package to npm that targeted cryptocurrency wallet credentials, specifically private keys and mnemonic seed phrases. The attack exploited the trust developers place in open-source dependencies to distribute wallet-stealing malware.

Why it matters: Developers using the compromised Injective SDK package face immediate risk of cryptocurrency wallet theft; practitioners should audit npm dependencies and check for the malicious package version in their supply chains.

VendorsGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary