
Hackers compromised a software package used by developers building on Injective (CRYPTO:INJ), exposing users to malware that could steal crypto wallet private keys and seed phrases.
Security firm Socket said the compromised npm package had about 50,000 weekly downloads, making the attack a serious supply chain security incident for developers.
“Any keys or mnemonics passed through affected packages should be treated as compromised,” Socket said.
Socket said the malware secretly copied private keys and seed phrases before sending them to a server that appeared to belong to the Injective network.
Injective Chief Executive Officer Eric Chen said the affected software versions have been deprecated, the issue has been fixed and no funds on the network were at risk.
Socket said the malware was downloaded more than 300 times before it was removed, but warned the wider campaign had not yet been fully contained.
Software supply chain attacks are becoming more common, with wallet compromises causing US$444 million in losses across 33 incidents during the first half of 2026, according to CertiK.
At the time of reporting, Injective price was $4.82.