Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
A major security breach occurred when unknown hackers infiltrated Injective Labs' GitHub repository and exploited it to release a harmful npm package designed to steal cryptocurrency wallet private keys and mnemonic seed phrases. This compromised version, @injectivelabs/sdk-ts@1.20.21, included deceptive telemetry features that siphoned off sensitive wallet data. Such incidents highlight the growing threat of supply chain attacks in the tech and crypto worlds, emphasizing the need for tighter security protocols across software development and distribution channels.
Original Source
Read the full article at Thehackernews →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.