{
"$type": "site.standard.document",
"bskyPostRef": {
"cid": "bafyreicbcxsjryura4c55q7qnulo7rpu57vkhlx2wbjmpdpiqrsa6gazv4",
"uri": "at://did:plc:ghkvexthfanuyq7fb5veq6tw/app.bsky.feed.post/3mqcp6basc3v2"
},
"coverImage": {
"$type": "blob",
"ref": {
"$link": "bafkreigpzmw2zivhnaon6ubnrc3xoi3b6hk5ppb4kobcgxvmtzra4zxkvm"
},
"mimeType": "image/jpeg",
"size": 292583
},
"path": "/2026/07/injective-labs-github-compromise-pushes.html",
"publishedAt": "2026-07-10T17:29:28.000Z",
"site": "https://thehackernews.com",
"tags": [
"@injectivelabs"
],
"textContent": "Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases.\n\nThe compromised version, @injectivelabs/sdk-ts@1.20.21, came embedded with fake telemetry functionality that exfiltrated data from cryptocurrency wallets. The version was",
"title": "Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages"
}