step-security · Crawled Jul 9, 2026
Injective npm Supply Chain Attack: 18 Packages Backdoored to Steal Crypto Wallet Keys
5 IoCs
Read original article ↗
AI Summary
On July 8, 2026, attackers compromised a trusted developer's account to inject a backdoor into the @injectivelabs/sdk-ts npm package, a core SDK for the Injective blockchain. The malicious code captured cryptocurrency wallet recovery phrases and private keys during wallet creation or loading and exfiltrated them to an attacker-controlled server disguised as legitimate infrastructure. The backdoor was distributed across 18 related npm packages for less than an hour before being detected and reverted, posing a significant risk to any application that installed the tainted versions during that window.
AI-extracted · verify before operational use
Indicators of Compromise 5 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | testnet[.]archival[.]chain[.]grpc-web[.]injective[.]network | Details → |
| Filename | src/utils/key-derivation-telemetry.ts | Details → |
| Filename | dist/esm/accounts-jQ1GSgaW.js | Details → |
| Filename | dist/cjs/accounts-Cy0p4lLW.cjs | Details → |
| SHA-512 | sha512-tmewc0hw2za38hncslizpwiz4mrcdg94b5tduaolqixksny6xre61iyffp0wunzpqtrepcazxxuqfyaqrqhfppa | Details → |