Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
ID: cfad6d73-15ae-5cbe-bb0e-7c4dde6a2b81
STIX ID: report--cfad6d73-15ae-5cbe-bb0e-7c4dde6a2b81
Feed Name: The Hacker News
Threat Score
Unknown actors compromised Injective Labs' GitHub and published a malicious npm package (@injectivelabs/[email protected]) that implanted fake telemetry to capture and exfiltrate cryptocurrency mnemonics and private keys; the poisoned release was also published across 17 additional @injectivelabs scoped packages via a trusted maintainer/pipeline, and users are advised to update to 1.20.23, treat keys as compromised, rotate them, and inspect transitive dependencies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
