Digest
CRITICAL

Injective Labs GitHub Compromise Leads to Crypto Wallet Stealer via npm

Threat actors compromised the Injective Labs SDK GitHub repository to publish a malicious npm package, @injectivelabs/sdk-ts@1.20.21. This package contained fake telemetry functionality designed to exfiltrate cryptocurrency wallet private keys and mnemonic seed phrases. This incident underscores the severe risks associated with compromised development infrastructure and software supply chains, particularly for cryptocurrency users.

← Back to the feed

Trending Tags