
Attackers Backdoored Injective SDK on npm to Steal Crypto Wallet Keys
A compromised Injective Labs SDK package on npm was used to harvest private keys and seed phrases, security researchers reported.
AfroEuropa Newsroom
AfroEuropa desk
A software supply-chain attack targeting the developer tools of blockchain project Injective has renewed concern over the security of open-source package ecosystems that underpin much of the crypto industry, including projects and teams active across Europe.
According to reporting from BleepingComputer and Cointelegraph, attackers gained access to the GitHub repository behind the Injective Labs software development kit (SDK) and used that access to publish a malicious version of the package on the Node Package Manager, commonly known as npm. The tampered package was designed to steal cryptocurrency wallet private keys and mnemonic seed phrases from affected environments.
Keep reading
Fake 'Leaked' GTA VI Build Turns Out to Be Malware Padded With Empty Data
A 113GB file posing as a playable Grand Theft Auto VI build is reportedly a 50KB virus surrounded by junk data, according to analysts who examined it.
Other highlights
Valve Marks 30 Years Since Its 1996 Founding
Valve, the studio behind Half-Life and the Steam platform, reaches its 30th anniversary after being founded in August 1996.
Follow the storyOne newsletter, two continents
The Bridge brings you the tech, startups, and leaders moving between Africa and Europe in one sharp email each morning. No spam, unsubscribe anytime.








