bleeping-computer · Crawled Jul 9, 2026

Injective SDK on npm infected with cryptocurrency wallet stealer

2 IoCs
Read original article ↗

AI Summary

Hackers compromised a contributor's GitHub account for the Injective Labs SDK project and published a malicious version (1.20.21) of the @injectivelabs/sdk-ts npm package. This supply-chain attack targeted developers building cryptocurrency-related applications, stealing wallet private keys and mnemonic seed phrases when SDK functions were used. The stolen data was exfiltrated via HTTP POST to a legitimate Injective Labs endpoint to blend in with normal traffic. The malicious package was downloaded 310 times before being deprecated, and 17 associated packages were also compromised.

AI-extracted · verify before operational use

Indicators of Compromise 2 extracted

Type Value Detail
Package @injectivelabs/sdk-ts Details →
GitHub Repo injectivelabs/sdk-ts Details →