Injective SDK compromised on GitHub, malicious npm package steals wallets
Source headline: Injective SDK on npm infected with cryptocurrency wallet stealer
Intelligence Summary
Attackers compromised the Injective Labs SDK GitHub repository. They then published a malicious package to npm using the project’s name and versioning. The package was designed to steal cryptocurrency wallet private keys and mnemonic seed phrases. This could allow stolen credentials to be used for unauthorized access and irreversible fund loss. Developers and users who installed the affected npm package should verify integrity and rotate any exposed wallet secrets immediately.
Recommended Action
Inventory where Injective SDK runs in your environment and treat this as an active remediation item. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.