AUTO-UPDATED

Injective SDK on npm infected with cryptocurrency wallet stealer

Hackers compromised the Injective Labs SDK GitHub repository to distribute a malicious npm package designed to steal cryptocurrency wallet private keys and mnemonic seed phrases from unsuspecting software developers.

Key Points

  • Attackers compromised a contributor's GitHub account on June 8 to inject malicious code into version 1.20.21 of the @injectivelabs/sdk-ts package.
  • The malware specifically targets wallet functions, exfiltrating sensitive seed phrases and private keys via HTTP POST requests to a public infrastructure endpoint.
  • Security researchers at Socket, Ox Security, and StepSecurity confirmed the malicious package was downloaded 310 times before being deprecated.
  • The compromised SDK is a critical tool for building decentralized finance applications, trading bots, and cryptocurrency wallets on the Injective blockchain.
  • Developers who utilized the affected version are advised to immediately transfer digital assets to new wallets and rotate all compromised security credentials.

Why it Matters

This supply-chain attack highlights the significant risks posed to the decentralized finance ecosystem when core development tools are weaponized to target end-user assets. By compromising a trusted software dependency, attackers can bypass traditional security measures and gain unauthorized access to private keys, potentially leading to irreversible financial losses for developers and their users.
BleepingComputer Published by Bill Toulas
Read original