EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

The compromised Injective SDK leaks wallet keys through false telemetry

2026-07-10 15:23:04
Bookmark

Malicious update leaks private key and mnemonic words from Injective development kit

Socket found that after an Injective development kit suffered a malicious update, the private key and mnemonic words were leaked. This update has been downloaded more than 300 times.

Event summary

Socket pointed out that a tampered Injective npm software package stole the user\'s private key and mnemonic words through fake telemetry. The malicious version was downloaded more than 300 times and further spread through 17 related Impressive Labs software packages.

Incident details

According to a report from security company Socket, version 1.20.21 of the @injectivelabs/sdk-ts npm package, which is downloaded about 50,000 times a week, was tampered with after a developer\'s GitHub account was compromised. Suspicious committing activity began on June 8, and the malicious version was subsequently promoted to 17 other software packages under the Impressive Labs npm namespace.

The security company stated that the malicious code intercepted the wallet key generation function, recorded the private key and recovery phrase, and encoded the data. The data was then sent to the website of a counterfeit Impressive server through forged telemetry information.

Socket warns: \"Any key or mnemonic used in an infected software package should be considered compromised.\" The company also warned that even if applications do not directly install the SDK, they may be threatened.

Although affected developers quickly detected and removed the malware package version, Socket believes the attack activity has not yet been fully contained.

Project response

Eric Chen, CEO of Injective, said that the affected version of npm has been deprecated and related problems have been fixed. Chen added that funds on the Injective network were not at risk, and Socket did not report whether the malware led to asset theft.

Targeted attack: Developers are targeted

Unlike attacking blockchain cryptography or smart contracts, this attack targets the development tools developers use to build wallets, exchanges and applications. The Security Alliance pointed out in its second-quarter threat report that attackers are increasingly using platforms such as GitHub, npm and Google to distribute malware.

The Security Alliance said that in some incidents, infected computers were used to push malicious code into the company\'s own GitHub repository, making an intrusion a channel for further spread. The report also listed more cross-platform malware packages that combine information thieves, remote access Trojans and backdoors, with increased attacks targeting the macOS platform.

Industry Background

In March this year, Axios \'npm version suffered a similar supply chain attack. The TrapDoor attack discovered in May targeted developers in the fields of cryptocurrency, decentralized finance, artificial intelligence and security. GitHub also disclosed an incident on May 20: unauthorized access to its internal warehouse after an employee\'s equipment was hacked.

According to CertiK data, wallet intrusion was the most costly cryptocurrency attack in the first half of 2026, causing a total of $444 million to be stolen in 33 incidents.

Aggressive is an interoperable Layer 1 network for decentralized financial applications. Data shows that the network\'s total lock-in value has dropped from a peak of $71 million in mid-2024 to $8.2 million, a drop of 88%. Earlier this year, community members approved Proposition IIP-617, which accelerates the scaling back of new INJ token issuance while retaining the existing token destruction mechanism.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP