Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening

    September 19, 2026

    Mathematicians Hate AI. They Can’t Quit It

    September 19, 2026

    Adopt This Data Center Plushie and Hear Its Piercing Scream

    September 19, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening
    • Mathematicians Hate AI. They Can’t Quit It
    • Adopt This Data Center Plushie and Hear Its Piercing Scream
    • If the AI Industry Followed Its Own Research, It Might Have Paused Already
    • Single-Phase Direct Liquid Cooling Is Proven for the Next Decade of Ultra-Dense Compute
    • Virtual Biotech Company Puts 37,000 AI Agents to Work on Drug Discovery
    • Here’s How an AI Slowdown Could Actually Be Enforced
    • Could AI really kill us all? Your questions, answered.
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Injective SDK on npm infected with cryptocurrency wallet stealer
    Cybersecurity

    Injective SDK on npm infected with cryptocurrency wallet stealer

    kirklandc008@gmail.comBy kirklandc008@gmail.comJuly 10, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Injective SDK on npm infected with cryptocurrency wallet stealer
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hackers compromised the Injective Labs SDK project’s GitHub repository and used it to publish a malicious package on the Node Package Manager (npm) that stole cryptocurrency wallet private keys and mnemonic seed phrases.

    Application security companies Socket, Ox Security, and StepSecurity detected the supply-chain attack via version 1.20.21 of the @injectivelabs/sdk-ts npm package.

    Injective SDK is a TypeScript/JavaScript software development kit (SDK) for building applications on the Injective blockchain, a Layer-1 blockchain focused on decentralized finance (DeFi), tokenized assets, and decentralized exchanges.

    The package has 50,000 weekly downloads on npm and is used by developers building cryptocurrency wallets, trading bots, decentralized exchanges, DeFi applications, and payment tools.

    According to the researchers, the attacker compromised a GitHub account belonging to a legitimate project contributor and made the first suspicious commits on June 8, publishing the malicious version of the package shortly afterward.

    The attacker also published version 1.20.21 for another 17 packages associated with the project, pinning all of them to the compromised SDK version.

    The legitimate account owner detected the compromise within minutes, reverted the changes, and published a clean release, version 1.20.23.

    However, developer systems fetching the malicious packages via an update or used them were likely compromised.

    Socket says the malicious version of the package was downloaded 310 times before it was deprecated, not removed, and the malicious GitHub release artifacts are still available.

    The researchers also note that the package has 87 direct dependencies on npm and very likely multiple additional transitive dependencies.

    A report from Ox Security warns that the 87 dependent packages had a cumulative download count of a little over 112,000.

    Targeting cryptocurrency wallets

    The malware activates when the developers use SDK functions that generate or import wallet keys, rather than upon installation.

    Once those functions are called, the malware captures the full mnemonic seed phrase and private key and encodes the data in base64. All the information is exfiltrated via an HTTP POST request to an Injective Labs public infrastructure endpoint to make the traffic appear legitimate.

    StepSecurity reports that the malware did not immediately transmit stolen secrets, but instead queued multiple keys and mnemonics for two seconds, bundled them in the HTTP request header, and sent them.

    The attackers may then use the mnemonic or private key to port the victim’s wallets to their own devices and access, use, or transfer their digital assets.

    Developers who suspect compromise should transfer their cryptocurrency to new wallets and rotate all secrets in their environment.

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    cryptocurrency Infected Injective npm SDK Stealer wallet
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    The Download: a “God-driven” cryptocurrency and a solar engineering roadmap

    September 10, 2026

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026

    The 3 types of people who will excel in the AI agent era, according to tech leaders

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    The best VPN routers of 2026: Expert tested and reviewed

    June 14, 20263 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening
    • Mathematicians Hate AI. They Can’t Quit It
    • Adopt This Data Center Plushie and Hear Its Piercing Scream
    • If the AI Industry Followed Its Own Research, It Might Have Paused Already
    • Single-Phase Direct Liquid Cooling Is Proven for the Next Decade of Ultra-Dense Compute

    Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening

    September 19, 2026

    Mathematicians Hate AI. They Can’t Quit It

    September 19, 2026

    Adopt This Data Center Plushie and Hear Its Piercing Scream

    September 19, 2026

    If the AI Industry Followed Its Own Research, It Might Have Paused Already

    September 19, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.