A backdoored developer kit for the Injective blockchain quietly siphoned wallet seed phrases and private keys before a rapid takedown.A backdoored developer kit for the Injective blockchain quietly siphoned wallet seed phrases and private keys before a rapid takedown.

Hackers Compromised Injective’s 50,000-Download SDK To Steal Seed Phrases From Developers

2026/07/10 13:09
Okuma süresi: 3 dk
Bu içerikle ilgili geri bildirim veya endişeleriniz için lütfen [email protected] üzerinden bizimle iletişime geçin.

Hackers slipped wallet-stealing malware into an official Injective (INJ) developer package that averages 50,000 weekly downloads, and the tainted release was fetched 310 times before a rapid cleanup.

Key Points:

Injective SDK Backdoor Details

Security firm Socket disclosed on Thursday that version 1.20.21 of the @injectivelabs/sdk-ts package on npm had been altered through a compromised contributor account on GitHub. The kit is a core building block for wallets, exchanges and trading bots on Injective, a layer-1 blockchain designed for decentralized finance.

The rogue code posed as harmless usage analytics and hooked the functions that turn a seed phrase or a raw private key into a usable signing key. Every time an application called them, it quietly recorded the secrets, batched them for two seconds and sent them to a server disguised as legitimate Injective infrastructure. The stolen material traveled inside a request header, letting it blend into ordinary traffic.

Automated publishing carried the same poisoned version across 17 related packages within minutes of the first malicious commit, widening exposure to teams that never installed the kit directly.

A commit-level analysis showed the payload went live on Jul. 8 and was pulled in under an hour, with a clean version 1.20.23 following shortly after.

Injective CEO Eric Chen reportedly said the issue is already fixed and no funds on the network are at risk. Still, the compromised release was only deprecated on npm rather than removed, leaving it available for download. Artifacts from the tainted build also remained on GitHub at the time of disclosure.

Also Read: Solana’s ETF Moment Gets Harder To Ignore After New Bitwise Filing

Why Crypto Wallet Keys Were The Target

Researchers described the compromise as "significant for developers and applications that handle Injective wallet workflows," though they did not specify whether any assets were stolen. Teams were urged to treat any key or mnemonic that touched the affected versions as compromised, move funds to fresh wallets and rotate every secret in their environments.

Attacks of this kind never touch a blockchain's cryptography. Intruders instead poison the trusted tools developers rely on, turning a single hijacked account into a distribution channel that can quietly reach thousands of downstream applications.

The compromised kit alone counts 87 other npm packages among its direct dependents, analysts reported.

The episode caps a punishing stretch for open-source crypto tooling, following a similar compromise of Axios npm releases in March and the TrapDoor malware campaign that hit crypto and DeFi developers in May. CertiK ranked wallet compromises as the most costly attack vector of the first half of 2026, with $444 million stolen across 33 incidents.

Read Next: Grok 4.5 Challenges OpenAI And Anthropic With Cheaper Agentic AI

Get Covered, Share 1M USDT

Get Covered, Share 1M USDTGet Covered, Share 1M USDT

Higher VVIP tiers, higher compensation odds.

Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen [email protected] ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Record Ads, Stock Down 7%

Record Ads, Stock Down 7%Record Ads, Stock Down 7%

Jul 29: Meta earnings face the market's question.