Hackers Backdoor Injective npm SDK to Steal Crypto Wallet Keys
Attackers backdoored the official Injective npm SDK on July 8, 2026, planting code that stole crypto wallet seed phrases and private keys across 18 packages. The poisoned version was downloaded 310 times before a clean release shipped. Here is how the attack worked.