
Attackers Backdoored Injective SDK on npm to Steal Crypto Wallet Keys
A compromised Injective Labs SDK package on npm was used to harvest private keys and seed phrases, security researchers reported.
AfroEuropa Newsroom
AfroEuropa desk
A software supply-chain attack targeting the developer tools of blockchain project Injective has renewed concern over the security of open-source package ecosystems that underpin much of the crypto industry, including projects and teams active across Europe.
According to reporting from BleepingComputer and Cointelegraph, attackers gained access to the GitHub repository behind the Injective Labs software development kit (SDK) and used that access to publish a malicious version of the package on the Node Package Manager, commonly known as npm. The tampered package was designed to steal cryptocurrency wallet private keys and mnemonic seed phrases from affected environments.
Keep reading
Hadrian raises €35.68 million to grow its agentic AI offensive security platform
The London and Amsterdam-based cybersecurity firm will use the funding to expand across EMEA and the U.S. and strengthen its engineering and research teams.
Other highlights
Xreal Opens Pre-Orders for Aura Android XR Glasses, Starting at $1,279
Xreal has begun accepting pre-orders for its Aura smart glasses in an initial set of markets, with wider availability promised soon.
Follow the storyOne newsletter, two continents
The Bridge brings you the tech, startups, and leaders moving between Africa and Europe in one sharp email each morning. No spam, unsubscribe anytime.








