Suspect attack incident: Malicious code sneaked into the npm package, and user keys were at risk of being leaked.
Suspect officially denied that user funds were damaged. Previously, the attacker implanted malicious code to steal wallet keys in the 18 official npm development packages of the project. At the same time, security companies warned that the attack had led to the exposure of private keys and mnemonics transmitted through the software.
What happened to the Injective?
The attack began when two malicious code changes were pushed directly to the main code branch by the author named \"thomas Ralee\"-a real developer who had previously contributed code to the project. It is worth noting that this change did not undergo code review or pull requests, which allowed malicious code to bypass security detection.
Malicious code discovered by security company Socket is hidden in version 1.20.21 of @injectivelabs/sdk-ts. The TypeScript SDK is used by wallets, exchange front-ends, and trading robots to build applications on Injective. The attacker added a fake analysis file that hooked on two key functions, PrivateKey.fromMnemonic() and PrivateKey.fromHex()-which are responsible for converting a user\'s mnemonic or original private key into a transaction signing key.
The malicious function, called trackKeyDerivation(), claims to collect user data for \"SDK optimization\", but in fact it steals keys and mnemonics transmitted through the software and sends them to a remote server. The server address is disguised as the official Impressive domain name, making detection more difficult.
The tampered version 1.20.21 is locked in another 17 official @injectivelabs packages, which means that even if users only use the relevant tools, they may be at risk of exposure. Although the malicious package only existed for less than an hour, the contaminated version has been downloaded more than 300 times. The SDK is usually downloaded approximately 50,000 times a week. A clean-up version 1.20.23 has been released to replace them.
Aggressive Labs responded directly to the incident on the X platform on Thursday, saying the problem had been identified and immediately resolved. \"Funds have never been at risk, and no funds have been damaged,\" Injective\'s official account wrote. Company CEO Eric Chen also stated that the affected version of npm has been deprecated and the problem has been fixed.
Socket said that as of the release of its report, the attack had not been fully contained and it did not say whether any assets were actually stolen.
How can users protect their wallets?
Developers are advised to immediately upgrade to clean version 1.20.23 or higher to remove malicious code. StepSecurity recommends that any application that has pulled this malicious version or cached copy should treat the wallet key it has touched as exposed and replace it immediately. Users should also check whether version 1.20.21 is referenced in the package-lock.json or yarn.lock file, as other packages may introduce it automatically.
CertiK reported that 33 wallet breaches occurred in the first half of 2026 resulted in a total of $444.5 million stolen.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
INJ