step-security · Crawled Jul 9, 2026

Injective npm Supply Chain Attack: 18 Packages Backdoored to Steal Crypto Wallet Keys

5 IoCs
Read original article ↗

AI Summary

On July 8, 2026, attackers compromised a trusted developer's account to inject a backdoor into the @injectivelabs/sdk-ts npm package, a core SDK for the Injective blockchain. The malicious code captured cryptocurrency wallet recovery phrases and private keys during wallet creation or loading and exfiltrated them to an attacker-controlled server disguised as legitimate infrastructure. The backdoor was distributed across 18 related npm packages for less than an hour before being detected and reverted, posing a significant risk to any application that installed the tainted versions during that window.

AI-extracted · verify before operational use

Indicators of Compromise 5 extracted

Type Value Detail
Domain testnet[.]archival[.]chain[.]grpc-web[.]injective[.]network Details →
Filename src/utils/key-derivation-telemetry.ts Details →
Filename dist/esm/accounts-jQ1GSgaW.js Details →
Filename dist/cjs/accounts-Cy0p4lLW.cjs Details →
SHA-512 sha512-tmewc0hw2za38hncslizpwiz4mrcdg94b5tduaolqixksny6xre61iyffp0wunzpqtrepcazxxuqfyaqrqhfppa Details →