The Injective npm package was maliciously modified; hackers attempted to steal wallet private keys and mnemonic phrases
Svmuu News: According to Socket’s monitoring, the Injective blockchain npm package @injectivelabs/sdk-ts was maliciously modified. Attackers compromised the developer’s GitHub account to inject malicious code designed to steal wallet private keys and mnemonic phrases, then encoded the stolen data and sent it to an address masquerading as a legitimate Injective network server. The package receives approximately 50,000 downloads per week. The malicious version 1.20.21 began showing suspicious commits on June 8 and has been locked into 17 other packages within the Injective Labs npm scope; users who have not directly installed this SDK may also be affected.
Source:Odaily · Source Link
Disclaimer: This content reflects only the author’s personal views and does not constitute any investment or financial advice. If you discover any content that violates regulations,Click to Report
24H Trending
-
1
Saudi Arabia adopts new, pricier route to export oil via Mediterranean port
-
2
An Analysis of the Multiple Meanings of ODA: Different Project Backgrounds and Investment Risk Assessments
-
3
Investors Rotate Out of Chip Stocks
-
4
Analysis of the Investment Value and Future Prospects of the LAMBO Token: An Examination of Multiple Projects
-
5
FALQOM Token Analysis: A Closer Look at the Falcon Finance (FF) Project and Its Future Prospects
-
6
A Complete Guide to OKX (OKX) Account Registration and Identity Verification
-
7
DUO Network Token (DUO) Value Analysis: Project Status and Investment Considerations
-
8
A Selection of USDT Trading and Exchange Platforms: An Analysis of the World’s Leading Stablecoin Trading Channels
-
9
What Is SSV Coin? An Analysis of the SSV Network’s Core Technology and Trading Platform
-
10
PRARE (Polkarare) Project Overview and Market Performance Analysis
Markets Today
Recommended Reading










