EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Effective SDK is attacked by supply chain

2026-07-10 18:02:08
Bookmark

How the attack unfolded

A supply chain attack penetrated the Injective ($INJ) developer ecosystem, when hackers implanted malware that stole wallet information into a widely used npm package. Security company Socket discovered the threat in version 1.20.21 of the injectivelabs/sdk-ts package, the official TypeScript SDK used to build applications on the Impressive blockchain.

The Aggressive SDK is a TypeScript/JavaScript development kit used to build DeFi applications, tokenized assets, and decentralized exchanges on the Aggressive blockchain. The package is downloaded approximately 50,000 times a week and is used by developers who develop cryptocurrency wallets, trading robots, decentralized exchanges and payment tools.

The malicious feature was introduced through code submitted by a developer\'s GitHub account, which had previously made multiple contributions to the repository. Suspicious submissions began on June 8, and since then the malicious version has been locked in 17 other packages within the scope of the Injective Labs npm. Malicious code hooks into functions normally used to generate wallet keys, and whenever a developer\'s application uses these functions, it secretly copies the mnemonic or private key. The stolen data is Base64 encoded and quietly sent via a POST request to an endpoint disguised as the Impressive Labs public infrastructure, mixing leaked traffic with normal network activity.

Scope of influence and developer guidance

The impact of this attack goes beyond direct users of the core SDK. The attacker also released version 1.20.21 in 17 additional packages within the scope of Aggressive Labs that relied on and locked in malicious SDK versions, so even developers who did not directly install the SDK could be affected. The infected version was downloaded about 310 times, but downloading does not mean that the wallet key must have been compromised. Dangerous code only runs when the app is processing private keys or recovering phrases.

Aggressive CEO Eric Chen said the issue has been fixed and the affected version on npm has been deprecated, adding that funds on the network are not at risk. Socket did not report whether the malware caused the theft of assets. All 18 affected packages were rereleased to clean versions with version 1.20.23 in approximately 49 minutes. Despite its quick response, Socket urged developers to treat all keys or mnemonics processed through affected packages as compromised, warning that apps could have been exposed even if the SDK was not installed directly. Developers should transfer funds, change keys and mnemonic words, and check transfer dependencies. Auditing direct dependencies alone is not enough.

The attack did not target blockchain cryptography or smart contracts, but rather the software developers use to build wallets, exchanges and applications. According to CertiK, wallet intrusions have become the attack category that caused the largest economic loss in the first half of 2026, with 33 incidents alone causing more than $444 million in losses.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP