Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

Unknown threat actors compromised the Injective Labs SDK project’s GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases.

The compromised version, @injectivelabs/sdk-ts@1.20.21, came embedded with fake telemetry functionality that exfiltrated data from cryptocurrency wallets. The version was

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Agency stole bestselling author’s book, used AI to relaunch as their own

Agency stole bestselling author’s book, used AI to relaunch as their own Source: Hacker News

ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories

ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories It’s dumb out there again. This week has the usual smell of prod on fire

TinySol, a tiny solitaire game for DOS

TinySol, a tiny solitaire game for DOS Source: Hacker News