← All stories
● Covered by 2 sources · 2 reportsMedium impact

Injective SDK npm Package Compromised to Steal Cryptocurrency Keys

🔄 Updated 83d ago — new reporting from The Hacker News
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Injective SDK npm package was compromised by hackers.
  • Version 1.20.21 was used to steal wallet keys via fake telemetry.
  • Compromised via a legitimate contributor's GitHub account.
  • 50,000 weekly users of the affected package face risks.
  • 17 associated packages also pinned to the compromised version.

SDK Compromise Details

Hackers compromised the Injective Labs SDK project's GitHub repository and published a malicious version on npm. This version, 1.20.21, was rigged to steal cryptocurrency wallet private keys and mnemonic seed phrases from developers using the package for decentralized applications.

Scope of the Compromise

The affected SDK is popular among developers building cryptocurrency wallets, trading bots, and decentralized exchanges, with an estimated 50,000 weekly downloads.

Additionally, 17 more packages linked to the SDK were affected, as they were pinned to utilize the compromised version, exposing even more users to risk.

Method of Attack

The attack was conducted by exploiting a compromised GitHub account of a legitimate contributor to the Injective SDK project. Through this account, hackers made unauthorized commits that introduced the malicious functionalities disguised as telemetry functions to exfiltrate sensitive data.

Response and Mitigation

The compromised npm package version has since been deprecated, though its artifacts remain downloadable from GitHub. Users of the SDK and its associated npm packages are urged to examine dependencies and update any affected software to secure their applications against further exploitation risks.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

The Injective Labs SDK's GitHub repository was hacked, leading to the release of a malicious npm package that steals cryptocurrency wallet private keys. This attack poses a significant risk to users relying on affected packages, as the compromised code can exfiltrate sensitive wallet information through disguised telemetry functions.

The Injective SDK's npm package was compromised, resulting in a malicious version that stole private keys and seed phrases from users' cryptocurrency wallets. This attack affects developers relying on the SDK for decentralized finance applications and highlights vulnerabilities in the software supply chain.