A compromised developer GitHub account was used to inject credential-stealing functionality into @injectivelabs/sdk-ts version 1.20.21, a popular npm package with ~50,000 weekly downloads. The malicious code hooks the fromMnemonic and fromHex functions to capture wallet private keys and mnemonic phrases, then exfiltrates them via POST requests to an abused InjectiveLabs infrastructure endpoint. The threat actor amplified impact by publishing 17 additional @injectivelabs scoped packages at version 1.20.21, all pinned to the malicious SDK version.
Injective Labs
1 post
Compromised Injective SDK npm Package Exfiltrates Wallet Keys and Mnemonics