Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

Unknown threat actors compromised the Injective Labs SDK project’s GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases.

The compromised version, @injectivelabs/sdk-ts@1.20.21, came embedded with fake telemetry functionality that exfiltrated data from cryptocurrency wallets. The version was

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Obituary: AmigaDOS developer Dr. Tim King has passed away

Obituary: AmigaDOS developer Dr. Tim King has passed away Source: Hacker News

CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing

How An AI math breakthrough ignited a controversy

How An AI math breakthrough ignited a controversy Source: Hacker News