Injective SDK on npm infected with cryptocurrency wallet stealer
Hackers compromised the Injective Labs SDK GitHub repository to publish a malicious npm package that steals cryptocurrency wallet private keys and seed phrases. This malware poses a direct threat to developers and users managing crypto assets.
Why it matters
This incident highlights the risk of supply chain attacks targeting software development tools crucial to the crypto ecosystem.
SOC impact
SOC teams should determine whether the organization or its third-party providers could be affected and monitor authentication activity for signs of credential misuse.
Recommended actions
- Determine whether affected users, domains, or third-party providers intersect with your organization.
- Monitor authentication logs for suspicious sign-ins, password spraying, or credential reuse.
- Review MFA coverage and initiate credential resets where exposure is confirmed.
Executive Summary
Hackers compromised the Injective Labs SDK GitHub repository to publish a malicious npm package that steals cryptocurrency wallet private keys and seed phrases. This malware poses a direct threat to developers and users managing crypto assets. This incident highlights the risk of supply chain attacks targeting software development tools crucial to the crypto ecosystem.
SOC Impact
SOC teams should determine whether the organization or its third-party providers could be affected and monitor authentication activity for signs of credential misuse.
Credential and Exposure Checks
- Determine whether affected users, domains, or third-party providers intersect with your organization.
- Monitor authentication logs for suspicious sign-ins, password spraying, or credential reuse.
- Review MFA coverage and initiate credential resets where exposure is confirmed.
Why It Matters
This incident highlights the risk of supply chain attacks targeting software development tools crucial to the crypto ecosystem.