# Injective Labs GitHub Hacked, Malicious npm Packages Steal Wallet Keys

Injective Labs' GitHub repository was compromised, leading to the publication of malicious npm packages that steal cryptocurrency wallet private keys. Users who installed these packages risk losing access to their funds. The incident underscores persistent supply-chain security risks in the blockchain ecosystem.

**Importance:** 4/5

## Sources

### Security
- [The Hacker News](https://thehackernews.com/2026/07/injective-labs-github-compromise-pushes.html) — Fri, 10 Jul 2026 22:59:28 +0530