← All stories
Security 5 sources

Hackers attempt to backdoor Injective npm package to steal wallet keys

Covered by 5 sources · 5 articles

5 outlets - including Cryptopolitan, Cryptopress and Cryptoadventure and 2 more - are covering this story. Injective has dismissed concerns that user funds were compromised after attackers planted wallet-key-stealing code in 18 of its official npm developer packages. Meanwhile, security firms warn that the attack exposed the private keys and see…

Covered by

All coverage

Injective says no funds at risk after npm packages backdoored to steal wallet keys
Cryptopolitan Jul 10, 21:20 UTC

Injective says no funds at risk after npm packages backdoored to steal wallet keys

Injective has dismissed concerns that user funds were compromised after attackers planted wallet-key-stealing code in 18 of its official npm developer packages. Meanwhile, security firms warn that the attack exposed the private keys and see…

Cryptopress Jul 10, 09:21 UTC

Injective npm Package Backdoor Targeted Wallet Keys Before Clean Release

Hackers pushed a malicious version of Injective’s TypeScript SDK to npm in a supply-chain attack designed to steal wallet recovery phrases and private keys from developer environments. The compromised release, @injectivelabs/[email protecte…

Injective npm Package Backdoor Targeted Wallet Keys Before Clean Release
Crypto Adventure Jul 10, 09:07 UTC

Injective npm Package Backdoor Targeted Wallet Keys Before Clean Release

Hackers pushed a malicious version of Injective’s TypeScript SDK to npm in a supply-chain attack designed to steal wallet recovery phrases and private keys from developer environments. The compromised release, @injectivelabs/[email protected],…

Hackers attempt to backdoor Injective npm package to steal wallet keys
Crypto Briefing News Jul 10, 03:24 UTC

Hackers attempt to backdoor Injective npm package to steal wallet keys

The incident highlights the critical need for enhanced security measures in software supply chains to protect sensitive crypto assets.

Hackers tried to backdoor Injective npm package to steal wallet keys
Cointelegraph Jul 10, 03:07 UTC

Hackers tried to backdoor Injective npm package to steal wallet keys

The incident is significant for developers and applications that handle Injective wallet workflows, Socket researchers said.