Injective software package hit by malicious supply chain attack – Details
Injective software package hit by malicious supply chain attack – Details
DeFi Intel is an entity-graph aggregator: we curate, tag and link crypto news to a typed knowledge graph of protocols, tokens, people and incidents. We do not republish the full article body. Use the link above to read the original report at Ambcrypto.
A hijacked maintainer account published a poisoned @injectivelabs/sdk-ts release that harvested wallet keys and spread to 18 dependent packages; it was reverted within about an hour with no reported fund losses.
Entities in this story
Want the full article?
Continue reading on Ambcrypto →