Injective SDK on npm infected with cryptocurrency wallet stealer
ID: 428182bd-5bd9-5286-874e-39ed7fb10c7e
STIX ID: report--428182bd-5bd9-5286-874e-39ed7fb10c7e
Feed Name: Bleeping Computer
A malicious release (v1.20.21) of the @injectivelabs/sdk-ts npm package — published after a GitHub contributor account was compromised — contained code that captured wallet mnemonics and private keys when SDK wallet-generation/import functions were called, encoded them in base64, and exfiltrated them via HTTP POST to an Injective Labs infrastructure endpoint; the malicious package was downloaded at least 310 times and 17 related packages were pinned to the compromised version, potentially affecting a broad set of developers and dependent projects.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
