Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesStocksEarnInstitutionAI & More
Security firm Socket discovers malicious code injected into the Injective blockchain npm package

Security firm Socket discovers malicious code injected into the Injective blockchain npm package

AiCoinAiCoin2026/07/10 03:22
Show original
According to Cointelegraph, security firm Socket discovered that the Injective blockchain’s npm package @injectivelabs/sdk-ts had been maliciously modified. Attackers infiltrated a developer’s GitHub account and implanted malicious code designed to steal wallet private keys and mnemonic phrases, sending the data to an address disguised as a legitimate Injective network server. This package is downloaded around 50,000 times per week. The malicious version 1.20.21 started showing suspicious commits on June 8 and was also locked in 17 other packages within the Injective Labs npm scope.
0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

Understand the market, then trade.
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold.
Trade now!