logo

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

ID: cfad6d73-15ae-5cbe-bb0e-7c4dde6a2b81

STIX ID: report--cfad6d73-15ae-5cbe-bb0e-7c4dde6a2b81

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-07-10

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

Unknown actors compromised Injective Labs' GitHub and published a malicious npm package (@injectivelabs/[email protected]) that implanted fake telemetry to capture and exfiltrate cryptocurrency mnemonics and private keys; the poisoned release was also published across 17 additional @injectivelabs scoped packages via a trusted maintainer/pipeline, and users are advised to update to 1.20.23, treat keys as compromised, rotate them, and inspect transitive dependencies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.