hacker-news · Crawled Jul 10, 2026
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
4 IoCs
Read original article ↗
AI Summary
Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and published a malicious npm package, @injectivelabs/[email protected], designed to steal cryptocurrency wallet private keys and mnemonic phrases. The malware was distributed through 17 additional scoped npm packages, increasing its reach to transitive users. The malicious code evaded detection by avoiding lifecycle scripts and exfiltrated sensitive data via HTTPS POST requests to a remote server.
AI-extracted · verify before operational use
Indicators of Compromise 4 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | testnet[.]archival[.]chain[.]grpc-web[.]injective[[.]]network | Details → |
| Package | @injectivelabs/[email protected] | Details → |
| GitHub Repo | injectivelabs/sdk-ts | Details → |
| GitHub User | thomasRalee | Details → |