AUTO-UPDATED

Hackers tried to backdoor Injective npm package to steal wallet keys

Hackers compromised the @injectivelabs/sdk-ts NPM package in a supply chain attack, attempting to steal cryptocurrency wallet private keys and seed phrases through malicious code injections.

Key Points

  • Security firm Socket identified that version 1.20.21 of the Injective SDK was modified via a compromised GitHub account starting June 8.
  • The malicious code was designed to hook into key-derivation functions to record and exfiltrate private keys and mnemonics to a fraudulent server.
  • Socket reported 310 downloads of the malicious package, though Injective Labs CEO Eric Chen stated the issue was resolved and claimed zero successful downloads.
  • The compromise extended to 17 other packages within the Injective Labs NPM scope, potentially exposing developers who did not install the SDK directly.
  • Injective Labs has deprecated the affected versions and confirmed that no funds on the blockchain network are currently at risk.

Why it Matters

This incident highlights the growing trend of supply chain attacks targeting developer tools rather than direct blockchain vulnerabilities. As attackers increasingly exploit trusted platforms like GitHub and NPM, developers must remain vigilant about the integrity of third-party software dependencies to prevent widespread wallet compromises.
Cointelegraph Published by Cointelegraph by Martin Young
Read original