Hackers Backdoor Injective Package in Bid to Steal Wallet Keys
Security protections for blockchain development tools face a serious challenge. Security firm Socket said a supply-chain attack targeting Injective's official blockchain development package was a warning sign. The popular npm package receives 50,000 downloads a week, and malicious code inserted into it could steal users' wallet private keys and seed phrases. Such software supply-chain attacks can bypass conventional defenses and have emerged as a new threat to decentralized finance.
On July 8, 2026, hackers compromised an Injective Labs maintainer account and published the malicious version 1.20.21 to the npm repository. It was detected and removed after 49 minutes but had already been downloaded more than 300 times. Injective confirmed that no funds were lost and released the safe version 1.20.23. Security researchers strongly urged developers to upgrade immediately and treat the private keys of any wallets potentially affected as compromised.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →