Hackers compromised the Injective Labs SDK project's GitHub repository and published a malicious version on npm. This version, 1.20.21, was rigged to steal cryptocurrency wallet private keys and mnemonic seed phrases from developers using the package for decentralized applications.
The affected SDK is popular among developers building cryptocurrency wallets, trading bots, and decentralized exchanges, with an estimated 50,000 weekly downloads.
Additionally, 17 more packages linked to the SDK were affected, as they were pinned to utilize the compromised version, exposing even more users to risk.
The attack was conducted by exploiting a compromised GitHub account of a legitimate contributor to the Injective SDK project. Through this account, hackers made unauthorized commits that introduced the malicious functionalities disguised as telemetry functions to exfiltrate sensitive data.
The compromised npm package version has since been deprecated, though its artifacts remain downloadable from GitHub. Users of the SDK and its associated npm packages are urged to examine dependencies and update any affected software to secure their applications against further exploitation risks.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The Injective Labs SDK's GitHub repository was hacked, leading to the release of a malicious npm package that steals cryptocurrency wallet private keys. This attack poses a significant risk to users relying on affected packages, as the compromised code can exfiltrate sensitive wallet information through disguised telemetry functions.
The Injective SDK's npm package was compromised, resulting in a malicious version that stole private keys and seed phrases from users' cryptocurrency wallets. This attack affects developers relying on the SDK for decentralized finance applications and highlights vulnerabilities in the software supply chain.