Hackers attempt to backdoor Injective npm package to steal wallet keys
Covered by 5 sources · 5 articles
5 outlets - including Cryptopolitan, Cryptopress and Cryptoadventure and 2 more - are covering this story. Injective has dismissed concerns that user funds were compromised after attackers planted wallet-key-stealing code in 18 of its official npm developer packages. Meanwhile, security firms warn that the attack exposed the private keys and see…
All coverage
Injective says no funds at risk after npm packages backdoored to steal wallet keys
Injective has dismissed concerns that user funds were compromised after attackers planted wallet-key-stealing code in 18 of its official npm developer packages. Meanwhile, security firms warn that the attack exposed the private keys and see…
Injective npm Package Backdoor Targeted Wallet Keys Before Clean Release
Hackers pushed a malicious version of Injective’s TypeScript SDK to npm in a supply-chain attack designed to steal wallet recovery phrases and private keys from developer environments. The compromised release, @injectivelabs/[email protecte…
Injective npm Package Backdoor Targeted Wallet Keys Before Clean Release
Hackers pushed a malicious version of Injective’s TypeScript SDK to npm in a supply-chain attack designed to steal wallet recovery phrases and private keys from developer environments. The compromised release, @injectivelabs/[email protected],…
Hackers attempt to backdoor Injective npm package to steal wallet keys
The incident highlights the critical need for enhanced security measures in software supply chains to protect sensitive crypto assets.
Hackers tried to backdoor Injective npm package to steal wallet keys
The incident is significant for developers and applications that handle Injective wallet workflows, Socket researchers said.