Hackers compromised the @injectivelabs/sdk-ts NPM package in a supply chain attack, attempting to steal cryptocurrency wallet private keys and seed phrases through malicious code injections.
Key Points
- Security firm Socket identified that version 1.20.21 of the Injective SDK was modified via a compromised GitHub account starting June 8.
- The malicious code was designed to hook into key-derivation functions to record and exfiltrate private keys and mnemonics to a fraudulent server.
- Socket reported 310 downloads of the malicious package, though Injective Labs CEO Eric Chen stated the issue was resolved and claimed zero successful downloads.
- The compromise extended to 17 other packages within the Injective Labs NPM scope, potentially exposing developers who did not install the SDK directly.
- Injective Labs has deprecated the affected versions and confirmed that no funds on the blockchain network are currently at risk.