hacker-news · Crawled Jul 10, 2026

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

4 IoCs
Read original article ↗

AI Summary

Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and published a malicious npm package, @injectivelabs/[email protected], designed to steal cryptocurrency wallet private keys and mnemonic phrases. The malware was distributed through 17 additional scoped npm packages, increasing its reach to transitive users. The malicious code evaded detection by avoiding lifecycle scripts and exfiltrated sensitive data via HTTPS POST requests to a remote server.

AI-extracted · verify before operational use

Indicators of Compromise 4 extracted

Type Value Detail
Domain testnet[.]archival[.]chain[.]grpc-web[.]injective[[.]]network Details →
Package @injectivelabs/[email protected] Details →
GitHub Repo injectivelabs/sdk-ts Details →
GitHub User thomasRalee Details →