{
  "$type": "site.standard.document",
  "bskyPostRef": {
    "cid": "bafyreicbcxsjryura4c55q7qnulo7rpu57vkhlx2wbjmpdpiqrsa6gazv4",
    "uri": "at://did:plc:ghkvexthfanuyq7fb5veq6tw/app.bsky.feed.post/3mqcp6basc3v2"
  },
  "coverImage": {
    "$type": "blob",
    "ref": {
      "$link": "bafkreigpzmw2zivhnaon6ubnrc3xoi3b6hk5ppb4kobcgxvmtzra4zxkvm"
    },
    "mimeType": "image/jpeg",
    "size": 292583
  },
  "path": "/2026/07/injective-labs-github-compromise-pushes.html",
  "publishedAt": "2026-07-10T17:29:28.000Z",
  "site": "https://thehackernews.com",
  "tags": [
    "@injectivelabs"
  ],
  "textContent": "Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases.\n\nThe compromised version, @injectivelabs/sdk-ts@1.20.21, came embedded with fake telemetry functionality that exfiltrated data from cryptocurrency wallets. The version was",
  "title": "Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages"
}