Injective SDK on npm infected with cryptocurrency wallet stealer
Attackers breached the GitHub repository of Injective Labs and used that access to push a malicious version of the project's SDK to npm, the widely used JavaScript package registry. The tampered package was designed to silently harvest cryptocurrency wallet private keys and seed phrases from developers who installed it.
Why this matters: This is a supply chain attack, which means the damage travels through trust. Developers installed what looked like a legitimate, official package. The theft happened quietly, in the background, before anyone knew something was wrong. Private keys and seed phrases are not like passwords you can reset. Lose them and your funds are gone. The real exposure here is not just to individual developers — it is to any application or service built on top of that SDK. One compromised repository can ripple into thousands of projects.
Who should care: Cybersecurity · Privacy officers · Administrators
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.