
Hackers Attempted Backdoor Attack via Injective npm Package
Vexoda Newsroom
A supply chain attack targeted a widely used npm package, aiming to steal cryptocurrency wallet keys. The incident highlights the growing threat of such attacks and their potential impact on developer
In a recent development that has sent shockwaves through the crypto community, security firm Socket discovered hackers attempting to backdoor an Injective npm (node package manager) package to steal private wallet keys. This incident underscores the vulnerability of software supply chains in cryptocurrency ecosystems.
The compromised @injectivelabs/sdk-ts version 1.20.21 was modified via a GitHub account breach, with suspicious commits starting on June 8th. The malicious code was distributed across 17 other packages within the Injective Labs npm scope, increasing its reach and potential impact significantly.
Socket explained that the malware hooks into wallet key-derivation functions, recording private keys and mnemonic seed phrases before exfiltrating them through fake telemetry. Any data passed through affected packages should be treated as compromised to prevent further security breaches.
While the Injective blockchain itself remains secure, this incident is significant for developers and applications handling wallet workflows. The attack highlights the importance of regular package updates and thorough code reviews in maintaining robust cybersecurity practices within the crypto space.
The implications are far-reaching. Similar supply chain attacks have targeted other platforms like Axios npm releases and a malware campaign called TrapDoor. These incidents indicate an increasing trend among attackers to leverage legitimate development tools as vectors for their malicious activities.
Traders should monitor ongoing security updates from package managers and developers, ensuring they stay informed about potential vulnerabilities in widely used software packages. Additionally, implementing multi-layered security measures can help mitigate the risk of such attacks.
Source: Cointelegraph. Summarized and rewritten by the Vexoda Newsroom. This is market news, not financial advice.