World News 24

Injective Labs SDK npm package compromised to steal cryptocurrency keys

Crypto & Finance · 2026-07-10T21:08:10.000Z

The supply-chain attack was detected by application security companies Socket, Ox Security, and StepSecurity via version 1.20.21 of the @injectivelabs/sdk-ts npm package, which ha…

The supply-chain attack was detected by application security companies Socket, Ox Security, and StepSecurity via version 1.20.21 of the @injectivelabs/sdk-ts npm package, which has 50,000 weekly downloads. Source: https://www.scworld.com/brief/injective-labs-sdk-npm-package-compromised-to-steal-cryptocurrency-keys