๐Ÿ“… Wednesday, 23 September 2026 ยท --:-- UTC Follow us
Ecosystem โ–ผ
ID EN
Paket Injective Dibajak - Kunci Dompet Diselundupkan Lewat 'Laporan Palsu' ke Server Tiruan

Injective Packages Hijacked - Wallet Keys Smuggled via ‘Fake Reports’ to Lookalike Server

Imagine downloading an official tool from a reputable crypto project, only to unknowingly hand over your wallet keys to attackers. That is precisely what just happened in the Injective ecosystem. Cybersecurity firm Socket discovered that an Injective developer package was deliberately injected with malicious code that silently copied user private keys and seed phrases - and the poisoned package was downloaded more than 300 times before being detected.

What makes this incident alarming is not the download count, but how it operates: virtually invisible.

Not a Blockchain Breach, but a Compromise of Developer Tools

According to Socket, version 1.20.21 of the @injectivelabs/sdk-ts package - which sees around 50,000 weekly downloads - was modified after a developer’s GitHub account was compromised. Suspicious commits began surfacing on June 8, and the poisoned release was subsequently pushed to 17 other packages under the official Injective Labs name.

The malicious code intercepted wallet key generation functions, captured private keys and recovery phrases, then encoded the data and transmitted it via ‘fake telemetry’ to a domain intentionally spoofing official Injective servers. By masquerading as ordinary diagnostic reports, the data exfiltration raised virtually no suspicion.

“Any key or mnemonic that has passed through the affected packages must be considered compromised,” Socket warned, noting that applications could be exposed even if they did not install the SDK directly. Such attacks target the software developers use to build wallets, exchanges, and applications - rather than attacking the network’s underlying cryptography or smart contracts.

Patched, but Not Entirely Safe

Injective CEO Eric Chen stated that the compromised npm releases have been deprecated and the vulnerability resolved, emphasizing that no funds on the Injective network were at risk. Although the developer whose account was hijacked quickly detected the intrusion and the malicious versions were removed, Socket believes the attack campaign may not be entirely over.

This is far from an isolated incident. Security alliance SEAL noted that attackers are increasingly leveraging platforms like GitHub, npm, and Google to distribute malware. A similar supply chain attack hit the Axios package in March, while wallet theft became the costliest crypto attack vector throughout the first half of 2026 - claiming $444 million across 33 incidents, according to data from CertiK.

A Critical Lesson for Everyday Users

Supply chain attacks like this shift the paradigm: you can be meticulous about safeguarding your seed phrase, yet still fall victim simply because an application you use was built on components poisoned far upstream. The practical takeaway is straightforward yet vital - treat any key that ever interacted with the affected software as compromised, and immediately migrate funds to a fresh wallet if in doubt. In crypto, even trust in ‘official sources’ now has its limits.

Sourced from crypto.news.


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
๐Ÿ“ฉ KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share