Close Menu
Altcoinvest
    What's Hot

    Bitcoin Treads Water As Gold, S&P 500 See Significant Gains

    August 5, 2026

    Война за будущее денег официально началась ⚠️ Кто будет контролировать наши финансы?

    August 5, 2026

    Cardano Reaches New Decentralization Milestone With Record Nakamoto Coefficient

    August 5, 2026
    Facebook X (Twitter) Instagram
    Altcoinvest
    • Bitcoin
    • Altcoins
    • Exchanges
    • Youtube
    • Crypto Wallets
    • Learn Crypto
    • bitcoinBitcoin(BTC)$64,391.001.30%
    • ethereumEthereum(ETH)$1,873.520.80%
    • tetherTether(USDT)$1.000.00%
    • binancecoinBNB(BNB)$599.732.20%
    • usd-coinUSDC(USDC)$1.000.00%
    • rippleXRP(XRP)$1.06-0.60%
    • solanaSolana(SOL)$74.000.50%
    • tronTRON(TRX)$0.327375-0.50%
    • Figure HelocFigure Heloc(FIGR_HELOC)$1.02-0.20%
    • HyperliquidHyperliquid(HYPE)$57.163.80%
    Altcoinvest
    Home»Crypto Wallets»Injective NPM Package Hacked to Steal Crypto Wallet Keys
    Injective NPM Package Hacked to Steal Crypto Wallet Keys
    Crypto Wallets

    Injective NPM Package Hacked to Steal Crypto Wallet Keys

    July 10, 2026
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hackers compromised a widely used Injective software package in a supply chain attack with malware designed to steal crypto wallet private keys, adding to a growing attack vector involving attackers using legitimate platforms to deliver malicious payloads.

    Security firm Socket discovered on Thursday that a popular npm (node package manager) package with around 50,000 weekly downloads used for building on the Injective blockchain was maliciously modified to steal wallet private keys and seed phrases.

    The large number of downloads makes the incident “significant for developers and applications that handle Injective wallet workflows,” Socket researchers said. The malicious code has since been removed.

    The software supply chain attack is a relatively new attack vector in which hackers don’t target a blockchain’s cryptography or smart contracts directly, but instead compromise trusted developer tools used to build wallets, exchanges and apps.

    Injective is an interoperable layer 1 designed for DeFi applications. Its usage has dwindled over the past two years, with total value locked shrinking by 88% to current levels of $8.2 million from its $71 million peak in mid-2024, according to DefiLlama. 

    Secretly copying private keys and phrases

    Version 1.20.21 of the @injectivelabs/sdk-ts npm package was modified through a compromised developer GitHub account, with suspicious commits beginning June 8. It was also pinned across 17 other packages in the Injective Labs npm scope, “exposing users who may not have installed the SDK [software development kit] directly,” Socket said.

    “The malicious release hooks wallet key-derivation functions, records private keys and mnemonics, and exfiltrates them through fake telemetry,” Socket explained. 

    The malicious code hooked into normal functions used to generate wallet keys, and whenever a developer’s app used these functions, it secretly copied the seed phrase or private key. The compromised data was then encoded and sent to a web address that looked like a legitimate Injective network server.

    “Any keys or mnemonics passed through affected packages should be treated as compromised,” Socket added. 

    Related: ‘TrapDoor’ malware targets crypto dev tools in supply chain attack

    Socket reported that the developer whose account was infiltrated quickly detected the compromise, but the malware had been downloaded more than 300 times, and “the campaign itself isn’t yet fully contained.”

    Injective CEO Eric Chen said, “it’s already fixed, and the affected versions on npm are already deprecated.” No funds on the network are at risk, he added, and Socket did not specify whether any funds were stolen in the incident. 

    The compromised npm package was downloaded 310 times. Source: Socket

    Wallet compromises most costly this year

    The Security Alliance (SEAL) said in its second-quarter threat report that attackers are increasingly using legitimate platforms like GitHub, npm and Google to deliver payloads.

    “In some cases, compromised systems are being used to push malicious code directly into a company’s own GitHub repositories, turning a single compromise into a distribution channel for the next one.”

    SEAL added that the malware itself has also gotten more comprehensive, “with cross-platform payloads, including a rise in macOS-specific campaigns, that combine infostealers, RATs (remote access trojans) and backdoor capabilities in a single package.”

    A similar supply chain attack hit Axios npm releases in March, while a malware campaign called TrapDoor was discovered in May targeting crypto, DeFi, AI and security developers.

    GitHub itself was exploited on May 20 when it reported unauthorized access to its internal repositories following the compromise of an employee’s device. 

    Wallet compromises were the most costly attack vector in the first half of 2026, with $444 million stolen across 33 incidents, CertiK reported Monday. 

    Features: Bitcoin’s quantum dilemma: Bigger blocks or STARK proofs?

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Bitcoin Treads Water As Gold, S&P 500 See Significant Gains

    August 5, 2026

    Does the Coldcard Attack Mean All Hardware Wallets Are Now Insecure?

    August 5, 2026

    AI Credit Crisis Could Push Bitcoin to $1 Million

    August 5, 2026

    Bitcoin Price Metrics Echo 2022 In Coldest Phase Since FTX Collapse

    August 5, 2026
    Add A Comment

    Comments are closed.

    Tweets by InfoAltcoinvest

    Top Posts

    Bitcoin Treads Water As Gold, S&P 500 See Significant Gains

    August 5, 2026

    Does the Coldcard Attack Mean All Hardware Wallets Are Now Insecure?

    August 5, 2026

    AI Credit Crisis Could Push Bitcoin to $1 Million

    August 5, 2026

    What is Doge Killer (LEASH) Crypto

    February 27, 2026

    New Cardano Wallet – Everything Will Get Better

    December 8, 2025

    Senator Cynthia Lummis Slams Democrats Over Clarity Act

    July 30, 2026

    US Treasury Sanctions Sinaloa Cartel Associates Over Crypto Money Laundering

    May 24, 2026

    Altcoinvest is a leading platform dedicated to providing the latest news and insights on the dynamic world of cryptocurrencies.

    We're social. Connect with us:

    Facebook X (Twitter)
    Top Insights

    Bitcoin Treads Water As Gold, S&P 500 See Significant Gains

    August 5, 2026

    Война за будущее денег официально началась ⚠️ Кто будет контролировать наши финансы?

    August 5, 2026

    Cardano Reaches New Decentralization Milestone With Record Nakamoto Coefficient

    August 5, 2026
    Get Informed

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.


    Facebook X (Twitter)
    • Home
    • About us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions
    © 2026 altcoinvest.com

    Type above and press Enter to search. Press Esc to cancel.