Injective software package hit by malicious supply chain attack – Details
In a software supply chain attack, malicious actors compromised the Injective Labs TypeScript SDK (@injectivelabs/sdk-ts v1.20.21) by uploading a tainted version to the npm registry. The attackers gained access to a legitimate contributor's GitHub account to distribute malicious commits. The compromised package, disguised as a routine update, contained malware that activated only when developers used specific wallet generation functions, stealing private keys and mnemonic seed phrases. This breach impacted approximately 50,000 weekly downloads and spread through transitive dependencies in 17 other Injective packages. While a clean version (v1.20.23) was later released, the malicious package remained accessible. Affected users are advised to rotate credentials, create new wallets, and move their funds.
ambcrypto07/10 15:03