Security News

Cybersecurity news aggregator

CRITICAL Attacks SC Media

Injective Labs SDK npm package compromised to steal cryptocurrency keys

A supply chain attack compromised the Injective Labs SDK npm package via a hijacked GitHub account, publishing a malicious version (1.20.21) that exfiltrated cryptocurrency wallet private keys and seed phrases when developers used SDK functions to generate or import keys. The legitimate owner reverted the changes, but systems that fetched the compromised version were affected. Developers must verify they are not using the malicious @injectivelabs/sdk-ts version 1.20.21 and should check all dependent packages for compromise.
Read Full Article →

Supply chain Injective Labs SDK npm package compromised to steal cryptocurrency keys July 10, 2026 Share By SC Staff Bleeping Computer reports that hackers compromised the Injective Labs SDK project's GitHub repository and used it to publish a malicious package on npm that stole cryptocurrency wallet private keys and mnemonic seed phrases. The supply-chain attack was detected by application security companies Socket, Ox Security, and StepSecurity via version 1.20.21 of the @injectivelabs/sdk-ts npm package, which has 50,000 weekly downloads. The attacker compromised a legitimate contributor's GitHub account and published the malicious version, affecting 17 other associated packages. Although the legitimate owner quickly reverted the changes, systems fetching the compromised packages were likely affected. The malware activates when developers use SDK functions to generate or import wallet keys, capturing the full mnemonic seed phrase and private key. This data is exfiltrated via an HTTP POST request to an Injective Labs public infrastructure endpoint. The malicious version was downloaded 310 times before being deprecated. The 87 direct dependencies of the package had a cumulative download count of over 112,000, indicating a wide potential impact on developers building cryptocurrency wallets, trading bots, decentralized exchanges, and DeFi applications. Source: Bleeping Computer SC Staff Related Supply chain OpenMandriva Linux project reportedly targeted in attempted sabotage after contributor dispute SC Staff July 10, 2026 The incident occurred after a contributor's abusive behavior reportedly led to some members leaving the project. Supply chain North Korean PolinRider supply chain attack targets 108 unique repos Steve Zurier July 6, 2026 Socket says the campaign remains active and more attacks are likely. Supply chain Aikido Security acquires Root.io to enhance open-source software patching SC Staff July 2, 2026 Root.io offers agentic vulnerability remediation, utilizing AI agents to research, write, test, and deploy patches for newly published vulnerabilities within minutes. Related Events Cybercast From code to cloud: Stopping attacks in the software supply chain On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds

Share this article