Discussion

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

Started by The Hacker News · 10 Jul 2026 20:40 · 21 Views · 0 Replies
Thread Starter #0
Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases.

The compromised version, @injectivelabs/[email protected], came embedded with fake telemetry functionality that exfiltrated data from cryptocurrency wallets. The version was

Okumaya devam et...

You must be logged in to reply.

0 quotes selected