Close Menu
Cryptoz7
    What's Hot

    Bitcoin ETF inflows, crypto narratives begin to brighten amid win streak

    August 28, 2026

    BlackRock buys $2B in Bitcoin and $961M in Ethereum over 8 days

    August 28, 2026

    Ripple (XRP) Makes Major Wall Street Push With New Institutional Trading Business

    August 28, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Bitcoin ETF inflows, crypto narratives begin to brighten amid win streak
    • BlackRock buys $2B in Bitcoin and $961M in Ethereum over 8 days
    • Ripple (XRP) Makes Major Wall Street Push With New Institutional Trading Business
    • Perplexity Computer taps OpenSea for real
    • New Crypto Pepeto Confirms Its DeFi Exchange Passed Final Testing as the Dogecoin Price Prediction Targets Past $1
    • Best Crypto Wallet Apps in 2026: Security, Fees and Features Compared
    • The SEC failed to pass crypto custody rules in 2023. But it’s trying again.
    • Bitcoin: $6.4 Billion Options Expire Tomorrow
    Facebook X (Twitter) Instagram
    Cryptoz7
    • Home
    • Altcoins
    • Bitcoin
    • DeFi & Web3
    • Ethereum
    • Guides
    • Latest News
    • Markets
    • Regulations
    Cryptoz7
    Home»Guides»Hackers tried to backdoor Injective npm package to steal wallet keys
    Hackers tried to backdoor Injective npm package to steal wallet keys
    Guides

    Hackers tried to backdoor Injective npm package to steal wallet keys

    cryptoz7By cryptoz7July 11, 2026No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

     
    cointelegraph.com
     + 1 more10 July 2026 11:46, UTC

    Hackers compromised a widely used Injective software package in a supply chain attack with malware designed to steal crypto wallet private keys, adding to a growing attack vector involving attackers using legitimate platforms to deliver malicious payloads.

    Security firm Socket discovered on Thursday that a popular npm (node package manager) package with around 50,000 weekly downloads used for building on the Injective blockchain was maliciously modified to steal wallet private keys and seed phrases.

    The large number of downloads makes the incident “significant for developers and applications that handle Injective wallet workflows,” Socket researchers said. The malicious code has since been removed.

    The software supply chain attack is a relatively new attack vector in which hackers don’t target a blockchain’s cryptography or smart contracts directly, but instead compromise trusted developer tools used to build wallets, exchanges and apps.

    Injective is an interoperable layer 1 designed for DeFi applications. Its usage has dwindled over the past two years, with total value locked shrinking by 88% to current levels of $8.2 million from its $71 million peak in mid-2024

    Secretly copying private keys and phrases

    Version 1.20.21 of the @injectivelabs/sdk-ts npm package was modified through a compromised developer GitHub account, with suspicious commits beginning June 8. It was also pinned across 17 other packages in the Injective Labs npm scope, “exposing users who may not have installed the SDK [software development kit] directly,” Socket said.

    “The malicious release hooks wallet key-derivation functions, records private keys and mnemonics, and exfiltrates them through fake telemetry,” Socket explained.

    The malicious code hooked into normal functions used to generate wallet keys, and whenever a developer’s app used these functions, it secretly copied the seed phrase or private key. The compromised data was then encoded and sent to a web address that looked like a legitimate Injective network server.

    “Any keys or mnemonics passed through affected packages should be treated as compromised,” Socket added.

    Socket reported that the developer whose account was infiltrated quickly detected the compromise, but the malware had been downloaded more than 300 times, and “the campaign itself isn’t yet fully contained.”

    Injective CEO Eric Chen said, “it’s already fixed, and the affected versions on npm are already deprecated.” No funds on the network are at risk, he added, and Socket did not specify whether any funds were stolen in the incident.


    The compromised npm package was downloaded 310 times

    Wallet compromises most costly this year

    The Security Alliance (SEAL) said in its second-quarter threat report that attackers are increasingly using legitimate platforms like GitHub, npm and Google to deliver payloads.

    “In some cases, compromised systems are being used to push malicious code directly into a company’s own GitHub repositories, turning a single compromise into a distribution channel for the next one.”

    SEAL added that the malware itself has also gotten more comprehensive, “with cross-platform payloads, including a rise in macOS-specific campaigns, that combine infostealers, RATs (remote access trojans) and backdoor capabilities in a single package.”

    A similar supply chain attack hit Axios npm releases in March, while a malware campaign called TrapDoor was discovered in May targeting crypto, DeFi, AI and security developers.

    GitHub itself was exploited on May 20 when it reported unauthorized access to its internal repositories following the compromise of an employee’s device.

    Wallet compromises were the most costly attack vector in the first half of 2026, with $444 million stolen across 33 incidents, CertiK reported Monday.

    Features:Bitcoin’s quantum dilemma: Bigger blocks or STARK proofs?

    Similar news (1)

    backdoor Hackers Injective package tried
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    cryptoz7
    • Website

    Related Posts

    Best Crypto Wallet Apps in 2026: Security, Fees and Features Compared

    August 28, 2026

    Unstoppable Domains Drops .crypto and .bitcoin Plans

    August 27, 2026

    How to Use Bitcoin (BTC): Beginner’s Guide

    August 27, 2026

    Crypto Business Bank Account: The 2026 Guide

    August 26, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Bitcoin ETF inflows, crypto narratives begin to brighten amid win streak

    August 28, 2026

    BlackRock buys $2B in Bitcoin and $961M in Ethereum over 8 days

    August 28, 2026

    Ripple (XRP) Makes Major Wall Street Push With New Institutional Trading Business

    August 28, 2026

    Subscribe to Updates

    Get the latest sports news from SportsSite about soccer, football and tennis.

    Our mission is to deliver timely, accurate, and easy-to-understand coverage of the fast-moving digital asset industry. Whether you're a beginner exploring cryptocurrency for the first time or an experienced investor following market trends, Cryptoz7.com provides valuable information to help you stay informed.

    Facebook X (Twitter) Instagram Pinterest YouTube
    Top Insights

    Bitcoin ETF inflows, crypto narratives begin to brighten amid win streak

    August 28, 2026

    BlackRock buys $2B in Bitcoin and $961M in Ethereum over 8 days

    August 28, 2026

    Ripple (XRP) Makes Major Wall Street Push With New Institutional Trading Business

    August 28, 2026
    Get Informed

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Get In Touch
    • Disclaimer
    • Privacy Policy
    • Terms and Conditions
    © 2026 Cryptoz7. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.