Security firm Socket discovered Thursday that hackers compromised version 1.20.21 of a widely used Injective blockchain software package, inserting malware designed to steal wallet private keys and seed phrases. The package, @injectivelabs/sdk-ts, had around 50,000 weekly downloads and was maliciously modified through a compromised developer GitHub account starting June 8. The malicious code hooked into wallet key-generation functions, secretly copied credentials, and exfiltrated them through a fake telemetry server disguised as a legitimate Injective endpoint. The compromised version was downloaded 310 times before removal, and Socket reported the campaign is not yet fully contained.
This matters because supply chain attacks on developer tools represent a growing attack vector that bypasses blockchain security entirely. The threat is to developers and applications handling Injective wallet workflows, not to the chain itself or to locked value. Injective CEO Eric Chen confirmed the malicious versions are deprecated and no on-chain funds are at risk. Socket did not specify whether any funds were stolen. Injective's total value locked currently sits at $8.2 million, down 88 percent from a $71 million peak in mid-2024, according to DefiLlama, meaning exposure is limited even if wallets generated with the compromised package are drained.
The incident adds to a pattern: a similar supply chain attack hit Axios npm releases in March, and a malware campaign called TrapDoor targeted crypto developers in May. The Security Alliance noted in its second-quarter threat report that attackers increasingly use legitimate platforms like GitHub, npm, and Google to deliver payloads, and that compromised systems are being used to push malicious code directly into company repositories. Wallet compromises were the most costly attack vector in the first half of 2026, with $444 million stolen across 33 incidents, per CertiK.
There is no macro trade here because the threat is to a single low-TVL chain's developer ecosystem, not to the broader market or to any major DeFi primitive. The malicious code targeted wallet generation workflows, not smart contract infrastructure or bridge logic, so there is no contagion path to other chains or protocols. The number of compromised downloads, 310, is small relative to the weekly install base, and the affected package has already been patched. Funding remains elevated at 0.7 basis points per eight hours, suggesting leveraged longs remain in control and unaffected by this news.
This becomes a trade if a subsequent disclosure reveals that stolen keys were used to drain a material amount from a major exchange or DeFi protocol, or if a similarly compromised package is discovered in a higher-TVL ecosystem like Ethereum mainnet tooling. Watch for follow-up reports from Socket or Injective Labs specifying whether any funds were actually exfiltrated and the total dollar value at risk.
The signal to watch is whether any large wallet drains tied to this compromise are reported in the next 48 to 72 hours. If none surface, the incident remains developer hygiene news with no market consequence. If drains appear, reassess based on the total stolen and whether the affected wallets belonged to protocol treasuries or exchanges.
Source: CoinTelegraph
