Compromised Injective SDK npm Package Exfiltrates Wallet Keys and Mnemonics
Blog post from Socket
A malicious release of the @injectivelabs/sdk-ts package version 1.20.21 was identified, compromising private keys and mnemonic phrases by integrating fake telemetry functionality into the package and 17 related packages. The malicious code, which exfiltrates sensitive information via a public infrastructure endpoint, was introduced through a GitHub account with a history of contributions to the project. Despite the quick response by the developer to contain the threat and deprecate the compromised version on npm, the package remains downloadable, posing a continuing risk. The incident underscores the importance of auditing dependencies, as many applications using Injective Labs' packages could be indirectly affected due to transitive dependencies. With approximately 50,000 weekly downloads, the potential impact is significant, though the actual damage was mitigated by the swift detection and response. Developers are advised to update to the clean version 1.20.23 and treat any private key or mnemonic phrase handled by these packages as compromised.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.