As cited
Copy frozen at (site build).
threat intel
Not-so-anonymous telemetry: The @injectivelabs/sdk-ts backdoor
A backdoored version of the @injectivelabs/sdk-ts npm package contained malicious code that harvested cryptocurrency wallet mnemonics and private keys under the guise of telemetry collection. The compromised package was available briefly before detection and removal. Developers who installed the affected version faced direct exposure to private key theft.
Why it matters: Developers and cryptocurrency platforms using @injectivelabs/sdk-ts are at risk of credential compromise and wallet theft; immediate review of dependency versions and rotation of any exposed credentials is essential.
- Source published
- First seen by Cybersecurity Tracker