Hackers compromised the Injective Labs SDK GitHub repository to distribute a malicious npm package designed to steal cryptocurrency wallet private keys and mnemonic seed phrases from unsuspecting software developers.
Key Points
- Attackers compromised a contributor's GitHub account on June 8 to inject malicious code into version 1.20.21 of the @injectivelabs/sdk-ts package.
- The malware specifically targets wallet functions, exfiltrating sensitive seed phrases and private keys via HTTP POST requests to a public infrastructure endpoint.
- Security researchers at Socket, Ox Security, and StepSecurity confirmed the malicious package was downloaded 310 times before being deprecated.
- The compromised SDK is a critical tool for building decentralized finance applications, trading bots, and cryptocurrency wallets on the Injective blockchain.
- Developers who utilized the affected version are advised to immediately transfer digital assets to new wallets and rotate all compromised security credentials.