PDA

Просмотр полной версии : Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages


AntichatNews
11.07.2026, 09:00
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhTNxzPo9jxkW3GuuZLBgtPOrG3vZ3va6E710jDJu_JF0 jCpyQ1JTpymdVwdSH2VHL6-Ib6YLInvKsuNwgFJxna1nvDhwKMZ_hycTik5OgQniZei2FQ59-F3s80lsnPmhQ1aJsr7qIWWrf63V0AtHQxd_1Nlk6LkVEheoN5l RYH8aTeBoJ-kM1-bOjUgAwa/s1700-e365/npm-malware-2.jpg

Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases. The compromised version, @injectivelabs/sdk-ts@1.20.21, came embedded with fake telemetry functionality that exfiltrated data from cryptocurrency wallets. The version was

Источник новости:
The Hacker News (https://thehackernews.com/2026/07/injective-labs-github-compromise-pushes.html)

Читать полностью (https://thehackernews.com/2026/07/injective-labs-github-compromise-pushes.html)