Socket @socket.dev · 14d

🚨 Socket detected a software supply chain compromise in @​injectivelabs/sdk-ts, a popular npm package with ~50,000 weekly downloads and 87 npm dependents. The malicious release hooks wallet key-derivation functions, records private keys and mnemonics, and exfiltrates them through fake telemetry.

5 likes 1 replies

?

Replies

Socket · 14d

The malicious 1.20.21 version was also pinned across 17 other @​injectivelabs scoped packages, exposing users who may not have installed the SDK directly. Any keys or mnemonics passed through affected packages should be treated as compromised. socket.dev/blog/comprom...