EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Aggressive claims that npm package was attacked by a backdoor attack to steal wallet keys, but the f

2026-07-11 12:16:29
Bookmark

Suspect attack incident: Malicious code sneaked into the npm package, and user keys were at risk of being leaked.

Suspect officially denied that user funds were damaged. Previously, the attacker implanted malicious code to steal wallet keys in the 18 official npm development packages of the project. At the same time, security companies warned that the attack had led to the exposure of private keys and mnemonics transmitted through the software.

What happened to the Injective?

The attack began when two malicious code changes were pushed directly to the main code branch by the author named \"thomas Ralee\"-a real developer who had previously contributed code to the project. It is worth noting that this change did not undergo code review or pull requests, which allowed malicious code to bypass security detection.

Malicious code discovered by security company Socket is hidden in version 1.20.21 of @injectivelabs/sdk-ts. The TypeScript SDK is used by wallets, exchange front-ends, and trading robots to build applications on Injective. The attacker added a fake analysis file that hooked on two key functions, PrivateKey.fromMnemonic() and PrivateKey.fromHex()-which are responsible for converting a user\'s mnemonic or original private key into a transaction signing key.

The malicious function, called trackKeyDerivation(), claims to collect user data for \"SDK optimization\", but in fact it steals keys and mnemonics transmitted through the software and sends them to a remote server. The server address is disguised as the official Impressive domain name, making detection more difficult.

The tampered version 1.20.21 is locked in another 17 official @injectivelabs packages, which means that even if users only use the relevant tools, they may be at risk of exposure. Although the malicious package only existed for less than an hour, the contaminated version has been downloaded more than 300 times. The SDK is usually downloaded approximately 50,000 times a week. A clean-up version 1.20.23 has been released to replace them.

Aggressive Labs responded directly to the incident on the X platform on Thursday, saying the problem had been identified and immediately resolved. \"Funds have never been at risk, and no funds have been damaged,\" Injective\'s official account wrote. Company CEO Eric Chen also stated that the affected version of npm has been deprecated and the problem has been fixed.

Socket said that as of the release of its report, the attack had not been fully contained and it did not say whether any assets were actually stolen.

How can users protect their wallets?

Developers are advised to immediately upgrade to clean version 1.20.23 or higher to remove malicious code. StepSecurity recommends that any application that has pulled this malicious version or cached copy should treat the wallet key it has touched as exposed and replace it immediately. Users should also check whether version 1.20.21 is referenced in the package-lock.json or yarn.lock file, as other packages may introduce it automatically.

CertiK reported that 33 wallet breaches occurred in the first half of 2026 resulted in a total of $444.5 million stolen.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP