Injective Resolves Malicious npm Package; INJ Trades Up
What Injective disclosed
Injective used its official X account to confirm a security incident affecting its developer tooling. In an “Important Announcement,” the team wrote that “a few news outlets and accounts have reported a potential compromise involving Injective’s npm packages,” adding a plain-language summary: “The issue was identified and resolved immediately. No funds were ever at risk, and no funds were compromised.”
The underlying issue was a software supply-chain attack on a JavaScript package Injective publishes for developers. Security firm Socket, whose post Injective reposted, described the compromise in the @injectivelabs/sdk-ts npm package — a library it said has roughly 50,000 weekly downloads and 87 npm dependents. According to Socket, the malicious release “hooks wallet key-derivation functions, records private keys and mnemonics, and exfiltrates them.” In other words, the tampered code targeted the credentials of developers and applications that pulled in the affected version, rather than the Injective chain itself.
How Injective responded
Bojan Angjelkoski, described in a reposted statement as Head of Technology at Injective, said the team “moved quickly to contain the recent SDK supply-chain attack” and that the response “didn’t stop at remediation.” He added that Injective “redesigned parts of our release infrastructure” to harden the publishing pipeline against a repeat.
That activity is visible on Injective’s public code repositories. The InjectiveLabs GitHub organization shows the injective-ts package — the TypeScript collection that includes the affected SDK — updated on July 9, 2026, alongside a fresh update to injective-lists dated July 10, 2026. The org lists 180 repositories and runs a public bug bounty program, reflecting an established security-disclosure posture around its open-source stack.
The distinction the team emphasized matters for readers: this was a compromise of a distribution channel used by builders, not a break of the Layer-1 network’s on-chain security. Injective’s messaging framed the exposure as limited to anyone who installed the malicious package build before it was pulled.
Did the incident move the market?
The reason this article exists is to quantify whether the disclosure and resolution registered in INJ’s price and trading data. Based on our CoinMarketCap data, the answer is that INJ showed no signs of a security-driven sell-off around the event.
As of the snapshot, INJ traded at about $4.90, up 5.41% over the prior 24 hours, according to our CoinMarketCap data. Over the trailing seven days the token was up 6.18%, meaning the period covering the disclosure and remediation coincided with gains rather than losses. That is the opposite of the pattern typically seen when a hack results in actual fund losses.
On liquidity, our CoinMarketCap data puts 24-hour trading volume at roughly $95.9 million against a market capitalization of about $489.7 million. That gives a volume-to-market-cap ratio of close to 20%, indicating active turnover but not the kind of extreme spike that accompanies panic selling or a forced repricing.
The longer-term picture is more mixed and predates this event: INJ is down 12.62% over the past 30 days, per our CoinMarketCap data. In context, the token entered the incident window in a monthly drawdown yet still posted positive 24-hour and 7-day moves — consistent with a market that treated the npm compromise as a contained developer-tooling issue rather than a threat to user funds or chain integrity.
Why the market reaction was muted
Several details in Injective’s own account help explain the limited price impact. First, the compromise hit a distribution package, and Injective stated no funds were at risk or lost. Second, the team said the malicious release was identified and resolved immediately, shortening any window of uncertainty. Third, the disclosure landed during a stretch of active product announcements — Injective’s blog and website show a run of launches, including a new website unveiled July 8, 2026, and continued rollouts around tokenization and AI-agent tooling.
Supply-chain attacks on npm packages are an industry-wide risk for any project that ships open-source SDKs, because a single tampered release can propagate to every downstream application that installs it. For readers tracking the broader Layer-1 sector, the episode is a reminder that operational security extends beyond consensus and smart contracts to the developer supply chain — and that how quickly a team detects, communicates, and remediates such an event shapes whether markets react at all.
The bottom line
Injective reported that a malicious build of its @injectivelabs/sdk-ts npm package — flagged by Socket as designed to steal private keys and mnemonics — was contained with no funds compromised, and that it rebuilt parts of its release infrastructure in response. Our CoinMarketCap data shows INJ up 5.41% over 24 hours and 6.18% over seven days at the time of the snapshot, with volume near $95.9 million and a market cap around $489.7 million. On the numbers available, the incident did not produce a measurable negative market reaction.
Coins in this story
Sources
Reporting is drawn from the primary sources listed above and CryptoNewsAlert's own licensed CoinMarketCap price data. See our editorial & data policy for how articles are produced and reviewed.
Nothing on this page is financial or investment advice. Cryptocurrency prices are volatile; do your own research.