Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Compromised Injective SDK npm Package Exfiltrates Wallet Keys and Mnemonics

Blog post from Socket

Post Details
Company
Date Published
Author
Karlo Zanki
Word Count
1,102
Company Posts That Month
23
Language
English
Hacker News Points
-
Post removed?
No
Summary

A malicious release of the @injectivelabs/sdk-ts package version 1.20.21 was identified, compromising private keys and mnemonic phrases by integrating fake telemetry functionality into the package and 17 related packages. The malicious code, which exfiltrates sensitive information via a public infrastructure endpoint, was introduced through a GitHub account with a history of contributions to the project. Despite the quick response by the developer to contain the threat and deprecate the compromised version on npm, the package remains downloadable, posing a continuing risk. The incident underscores the importance of auditing dependencies, as many applications using Injective Labs' packages could be indirectly affected due to transitive dependencies. With approximately 50,000 weekly downloads, the potential impact is significant, though the actual damage was mitigated by the swift detection and response. Developers are advised to update to the clean version 1.20.23 and treat any private key or mnemonic phrase handled by these packages as compromised.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.