Mark RadarMARK RADAR
About
EN
Sign in

Hackers Backdoor Injective Package in Bid to Steal Wallet Keys

1 reports · First detected 2026-07-10 · Last active 2026-07-10

Security protections for blockchain development tools face a serious challenge. Security firm Socket said a supply-chain attack targeting Injective's official blockchain development package was a warning sign. The popular npm package receives 50,000 downloads a week, and malicious code inserted into it could steal users' wallet private keys and seed phrases. Such software supply-chain attacks can bypass conventional defenses and have emerged as a new threat to decentralized finance.

On July 8, 2026, hackers compromised an Injective Labs maintainer account and published the malicious version 1.20.21 to the npm repository. It was detected and removed after 49 minutes but had already been downloaded more than 300 times. Injective confirmed that no funds were lost and released the safe version 1.20.23. Security researchers strongly urged developers to upgrade immediately and treat the private keys of any wallets potentially affected as compromised.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)