CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2343

As cited

Copy frozen at (site build).

breaches incidents

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

Unknown threat actors compromised the Injective Labs SDK GitHub repository and published a malicious npm package that impersonated legitimate telemetry to steal cryptocurrency wallet private keys and mnemonic seed phrases. The compromised package version @injectivelabs/sdk-ts@1.20.21 was distributed through the npm registry to affect users of the SDK.

Why it matters: Developers and cryptocurrency users relying on Injective Labs SDK are at immediate risk of wallet compromise; review npm package versions and rotate any affected keys or seed phrases.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

breaches incidents

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

Unknown threat actors compromised the Injective Labs SDK GitHub repository and published a malicious npm package version 1.20.21 containing fake telemetry code designed to steal cryptocurrency wallet private keys and seed phrases. The compromised package was distributed through the public npm registry.

Why it matters: Developers using the Injective Labs SDK face immediate risk of wallet compromise; anyone who installed @injectivelabs/sdk-ts@1.20.21 should rotate affected cryptocurrency keys and seed phrases immediately.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

breaches incidents

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

Unknown threat actors compromised the Injective Labs SDK GitHub repository and published a malicious npm package version 1.20.21 containing fake telemetry code designed to steal cryptocurrency wallet private keys and seed phrases. The compromised package was distributed through the public npm registry.

Why it matters: Developers using the Injective Labs SDK face immediate risk of wallet compromise; anyone who installed @injectivelabs/sdk-ts@1.20.21 should rotate affected cryptocurrency keys and seed phrases immediately.

VendorsGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary