Injective has resolved security issues related to the npm package, and user funds have not been compromised
Injective's official account posted on the X platform, stating that recent media reports have covered news about "potential security risks involving the Injective npm package." This issue has been promptly identified and resolved. User funds have never been at risk and have not suffered any losses.
The official statement indicated that its security monitoring system detected the issue immediately and quickly marked the affected package version as deprecated, while replacing it with a new version, thus blocking the risk before the malicious package could be downloaded.
As a result, the download volume of the malicious package is zero, and it has not affected users; the security of user funds has also not been threatened. Injective's npm package is one of the most widely used SDKs in the cryptocurrency field, and the official team has now implemented optimization measures to ensure that such attack attempts cannot occur again.






