Compromised @injectivelabs/sdk-ts exfiltrates wallet keys through fake telemetry
ID: 6d8ef54f-edd6-5968-b933-97c9c245477b
STIX ID: report--6d8ef54f-edd6-5968-b933-97c9c245477b
Feed Name: Aikido Security's Blog
A malicious npm release, @injectivelabs/[email protected], included an injected infostealer that hooks PrivateKey.fromMnemonic and fromHex to capture wallet seed phrases and raw private keys, batching and exfiltrating them in the X-Request-Id header to a spoofed Injective subdomain (testnet.archival.chain.grpc-web.injective.network). The poisoned SDK was republished across 17 other @injectivelabs packages via hard dependency pins to enable transitive compromise; the malicious version was live for under an hour, downloaded 310 times, and has been deprecated but remains downloadable—affected keys should be rotated and funds moved, and users should upgrade to the clean 1.20.23.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
