Skip to content

Not-So-Anonymous Telemetry The @injectivelabs/sdk-ts Backdoo... - #2831

Open
carlospolop wants to merge 1 commit into
masterfrom
update_Not-So-Anonymous_Telemetry_The_injectivelabs_sdk_0a5ed7b8e7676b8e
Open

Not-So-Anonymous Telemetry The @injectivelabs/sdk-ts Backdoo...#2831
carlospolop wants to merge 1 commit into
masterfrom
update_Not-So-Anonymous_Telemetry_The_injectivelabs_sdk_0a5ed7b8e7676b8e

Conversation

@carlospolop

Copy link
Copy Markdown
Collaborator

🤖 Automated Content Update

This PR was automatically generated by the HackTricks News Bot based on a technical blog post.

📝 Source Information

🎯 Content Summary

Incident overview

On July 8, 2026, an attacker inserted a credential-stealing backdoor into version 1.20.21 of the npm package @injectivelabs/sdk-ts, the TypeScript SDK used by applications interacting with the Injective blockchain. The package had approximately 175,000 monthly downloads and more than 30,000 weekly downloads. No CVE is identified in the post.

The malicious source was introduced by GitHub commit

@carlospolop

Copy link
Copy Markdown
Collaborator Author

🔗 Additional Context

Original Blog Post: https://securitylabs.datadoghq.com/articles/not-so-anonymous-telemetry-injectivelabs-sdk-ts-backdoor

Content Categories: Based on the analysis, this content was categorized under "Generic Hacking → Exfiltration / Software Supply-Chain Attacks, with a cross-reference from Blockchain & Crypto".

Repository Maintenance:

  • MD Files Formatting: 1029 files processed

Review Notes:

  • This content was automatically processed and may require human review for accuracy
  • Check that the placement within the repository structure is appropriate
  • Verify that all technical details are correct and up-to-date
  • All .md files have been checked for proper formatting (headers, includes, etc.)

Bot Version: HackTricks News Bot v1.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant