As cited
Copy frozen at (site build).
breaches incidents
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
Unknown threat actors compromised the Injective Labs SDK GitHub repository and published a malicious npm package that impersonated legitimate telemetry to steal cryptocurrency wallet private keys and mnemonic seed phrases. The compromised package version @injectivelabs/sdk-ts@1.20.21 was distributed through the npm registry to affect users of the SDK.
Why it matters: Developers and cryptocurrency users relying on Injective Labs SDK are at immediate risk of wallet compromise; review npm package versions and rotate any affected keys or seed phrases.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
breaches incidents
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
Unknown threat actors compromised the Injective Labs SDK GitHub repository and published a malicious npm package version 1.20.21 containing fake telemetry code designed to steal cryptocurrency wallet private keys and seed phrases. The compromised package was distributed through the public npm registry.
Why it matters: Developers using the Injective Labs SDK face immediate risk of wallet compromise; anyone who installed @injectivelabs/sdk-ts@1.20.21 should rotate affected cryptocurrency keys and seed phrases immediately.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
breaches incidents
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
Unknown threat actors compromised the Injective Labs SDK GitHub repository and published a malicious npm package version 1.20.21 containing fake telemetry code designed to steal cryptocurrency wallet private keys and seed phrases. The compromised package was distributed through the public npm registry.
Why it matters: Developers using the Injective Labs SDK face immediate risk of wallet compromise; anyone who installed @injectivelabs/sdk-ts@1.20.21 should rotate affected cryptocurrency keys and seed phrases immediately.
- Source published
- First seen by Cybersecurity Tracker