#InjectiveLabs
🚨 Socket detected a software supply chain compromise in @​injectivelabs/sdk-ts, a popular npm package with ~50,000 weekly downloads and 87 npm dependents.

The malicious release hooks wallet key-derivation functions, records private keys and mnemonics, and exfiltrates them through fake telemetry.
July 9, 2026 at 2:17 PM
The latest update for #AikidoSecurity includes "How to maintain code quality standards with AI code and vibe coding" and "Compromised @injectivelabs/sdk-ts exfiltrates wallet keys through fake telemetry".

#Cybersecurity #AppSec #DevSecOps https://opsmtrs.com/48vGyRP
Aikido
Aikido Security is an automated application security platform designed specifically for software engineering teams.
opsmtrs.com
July 13, 2026 at 3:33 AM
Injective Labs' GitHub was breached, releasing npm packages that steal crypto wallet data. #InjectiveLabs #GitHubBreach #npm #SupplyChainAttack #Cybersecurity #Blockchain thedailytechfeed.com/injective-la...
July 10, 2026 at 6:04 PM
@injectivelabs/sdk-ts 12021 — When a Trusted SDK Turns Into a Crypto-Draining Backdoor + Video

Introduction The npm ecosystem witnessed yet another sophisticated supply chain attack on July 9, 2026, when the widely-used `@injectivelabs/sdk-ts` package — a TypeScript SDK for building Injective…
@injectivelabs/sdk-ts 12021 — When a Trusted SDK Turns Into a Crypto-Draining Backdoor + Video
Introduction The npm ecosystem witnessed yet another sophisticated supply chain attack on July 9, 2026, when the widely-used `@injectivelabs/sdk-ts` package — a TypeScript SDK for building Injective blockchain applications with roughly 50,000 weekly downloads — was compromised with malicious code designed to exfiltrate wallet private keys and mnemonic phrases. What makes this incident particularly alarming is that the attack occurred on the very same day npm v12 was released with enhanced security features, proving that registry-side defenses alone cannot stop determined adversaries.
undercodetesting.com
July 10, 2026 at 3:15 AM
@socket.dev
Malicious @injectivelabs/sdk-ts@1.20.21 and 17 related packages exfiltrate wallet private keys and mnemonics via hooked key derivation functions.
-
...
Compromised Injective SDK npm Package Exfiltrates Wallet Keys
socket.dev
July 9, 2026 at 4:13 PM
⚠️ SUPPLY CHAIN ATTACK: The official Injective Labs SDK on npm (@injectivelabs/sdk-ts) was hijacked to distribute crypto-stealing malware. The malicious package exfiltrates private keys and seed phrases from developers. 💻 #npm #SupplyChain #CyberSec...

🌐 cyber[.]netsecops[.]io
Injective Labs SDK on npm Hijacked in Crypto-Stealing Supply Chain Attack
A malicious version of the @injectivelabs/sdk-ts npm package was published after a GitHub compromise, designed to steal cryptocurrency wallet private keys...
cyber.netsecops.io
July 13, 2026 at 7:05 PM
⚠️ SUPPLY CHAIN ATTACK: The official Injective Labs SDK on npm (@injectivelabs/sdk-ts) was hijacked to distribute crypto-stealing malware. The malicious package exfiltrates private keys and seed phrases from developers. 💻 #npm #SupplyChain #CyberSec...

🌐 cyber[.]netsecops[.]io
Injective Labs SDK on npm Hijacked in Crypto-Stealing Supply Chain Attack
A malicious version of the @injectivelabs/sdk-ts npm package was published after a GitHub compromise, designed to steal cryptocurrency wallet private keys from developers.
cyber.netsecops.io
July 10, 2026 at 3:56 PM
Injective SDK Supply Chain Attack Exposed Developers to Cryptocurrency Wallet Theft #CryptocurrencyWalletSecurity #CyberSecurity #DeFiSecurity
Injective SDK Supply Chain Attack Exposed Developers to Cryptocurrency Wallet Theft
  InjectiveLabs/SDK-TS, a widely used package, was briefly published on Node Package Manager (npm) as a malicious version after attackers gained access to a legitimate contributor's GitHub account, exposing developers to the theft of cryptocurrency wallet credentials. Several security researchers from Socket, Ox Security, and StepSecurity identified the supply chain attack as targeting Injective Labs' TypeScript/JavaScript SDK, which is used to develop applications based on Injective's blockchain. The SDK is widely adopted by developers who create cryptocurrency wallets, decentralized finance (DeFi) applications, decentralized exchanges, trading bots, and payment platforms, with approximately 50,000 downloads per week on NPM.  A significant security issue is the responsibility of the SDK when it comes to creating and importing cryptocurrency wallets, as it occupies a critical position in the development process. Developers and end users alike are particularly vulnerable to any compromise of the SDK because the wallet creation functions are crucial to the handling of users' mnemonic recovery phrases and private keys.  Researchers have determined that hackers gained access to a legitimate contributor's GitHub account on June 8 and introduced malicious code, which was later released as version 1.20.21 for the @injectivelabs/sdk-ts package. Additionally, 17 additional Injective-related packages were referenced by the compromised release, resulting in a significant impact on downstream projects. According to security researchers, attackers compromised a legitimate maintainer's account after exploiting the trust-worthy GitHub publishing workflow of the project.  As opposed to stealing an NPM publishing token or creating a fake package, the malicious version was distributed through the repository's normal release process, making the compromise appear genuine. Package maintainers detected the malicious activity within minutes, reverting the unauthorized changes and releasing a version that is free of malicious activity, 1.20.23.  Nevertheless, systems that downloaded or updated the compromised package during the brief exposure window may still have been affected. In contrast to conventional malware that is executed during installation, the injected code is activated when developers create or import cryptocurrency wallets using SDK functions.  When this was achieved, the malware captured private wallet keys and mnemonic seed sentences, encoded the information, and sent it via HTTP POST request to what appeared to be an official Injective Labs infrastructure endpoint in order to blend into normal network traffic. As a method of minimizing detection, the malware disguised its outbound communication as legitimate injective network traffic in order to prevent detection.  By capturing multiple wallet secrets temporarily, encoding them, and transmitting them as a single request, the malicious activity was able to blend in with blockchain-related communications, avoiding detection. The malware, according to StepSecurity researchers, collected wallet secrets for approximately two seconds before bundling them into a single request to minimize suspicion while maximizing the amount of data stolen.  In a recent report, Socket reported that 310 malicious packages had been downloaded before they were deprecated, but there is reportedly still availability of the associated malicious GitHub release artifacts. As a consequence of Ox Security's warning, the compromised SDK is dependent on 87 direct NPM packages, accounting for more than 112,000 cumulative downloads, illustrating the risk to a larger supply chain. Researchers noted that even though the malicious payload was contained within @injectivelabs/sdk-ts, the compromised release affected 17 additional injective packages that depended on the infected SDK version. This could have resulted in developers installing the backdoored package unknowingly through normal project dependencies, thereby significantly expanding the attack's impact.  It is advised that developers who suspect they may have installed the affected version transfer cryptocurrency assets immediately into new wallets, replace compromised private keys and seed phrases, and rotate any sensitive credentials stored within their development environment immediately. The incident underlines the growing threat posed by software supply chain attacks, particularly within the cryptocurrency ecosystem where a compromised development dependency may result in a significant financial loss to both developers and end users. Due to the increasing sophistication of software supply chain attacks, organizations and developers must strengthen dependency verification, monitor package integrity, and respond quickly to compromised components so that credential theft and downstream compromise can be reduced.
dlvr.it
July 11, 2026 at 5:38 AM
The latest update for #AikidoSecurity includes "Compromised @injectivelabs/sdk-ts exfiltrates wallet keys through fake telemetry" and "#AI #Pentesting Buyer's Guide: How to evaluate AI pentesting vendors".

#Cybersecurity #AppSec #DevSecOps https://opsmtrs.com/48vGyRP
Aikido
Aikido Security is an automated application security platform designed specifically for software engineering teams.
opsmtrs.com
July 9, 2026 at 11:41 PM
Injective Labs GitHub Compromise Distributes Malicious npm Package Targeting Crypto Wallet Keys #CryptoWallet #cyberattack #CyberSecurity
Injective Labs GitHub Compromise Distributes Malicious npm Package Targeting Crypto Wallet Keys
 Cybersecurity researchers have detected a software supply chain attack in which threat actors compromised the Injective Labs SDK GitHub repository and utilized it to distribute a backdoored version of the npm package containing cryptocurrency wallet credentials stealing capabilities. Researchers at security company Socket have identified that the attackers distributed the malicious code in the @injectivelabs/sdk-ts version 1.20.21 after compromising the GitHub account of one of the trusted maintainers.  The compromised package was published to the npm registry on July 8, 2026, and subsequently deprecated. Nevertheless, the distribution channel for the malicious artifacts remained available on GitHub at the time of publication. The attackers distributed the backdoored SDK to 17 other @injectivelabs packages, including the wallet, utility, networking, and crypto modules. Since the packages include various apps as dependencies, developers who did not directly install the SDK might also be affected.  Unlike traditional supply chain malware that typically persists in the compromised software at installation time, the detected backdoor was not activated when the developers installed the package. Rather, the malicious code was designed to exfiltrate the cryptographic assets when the developers used the SDK’s wallet generation feature.  Thus, the threat actors could hide the malicious payload’s presence by avoiding the use of suspicious scripts typically associated with malware. The detected malware consisted of modified cryptographic functions that replaced the legitimate implementation with the backdoor, which the attackers masked as a performance telemetry component. The additional function exfiltrated the cryptographic assets, including the mnemonic seed phrase and private key generation details, required to recreate the cryptocurrency wallet.  Researchers noted that the malware persisted in the compromised repositories by sending the collected data to the remote server in aggregated fashion to avoid suspicion by grouping multiple exfiltration requests into one encrypted HTTPS session. The security analysts at OX Security stated that the detected threat was capable of intercepting the master recovery phrase used to seed cryptocurrency wallets. Since the mnemonic seed phrase gives the adversary full access to the wallet funds, threat actors could reproduce the cryptographic assets to gain unauthorized access to the blockchain assets.  The malware’s distribution channel was compromised using the trusted publishing infrastructure and OpenID Connect (OIDC) publishing pipeline. The detected threat utilized the legitimate account of one of the maintainers, which implies that the attackers did not have to use supply chain malware or impersonate the project on a third-party registry. The developers who installed the affected package should switch to the latest version, 1.20.23, which has been released.  The security analysts advise the developers to consider all private keys and mnemonic phrases generated with the compromised version of the code as compromised and take the appropriate actions to rotate the cryptographic assets. Moreover, the developers should review their project dependencies to ensure that they do not use the affected versions of the packages indirectly.  The incident demonstrated how the threat actors could target the software supply chain to compromise the cryptocurrency ecosystem and gain unauthorized access to the crypto assets by compromising the open-source developer infrastructure.
dlvr.it
July 11, 2026 at 2:44 PM
The Injective npm backdoor hooked fromMnemonic() and stole crypto seed phrases as fake telemetry. https://intel.threadlinqs.com/threat/TL-2026-2366 #ThreatIntel #injectivesdktelemetrybackdoor #Injective #NpmSupplyChain
September 7, 2026 at 12:07 PM
A 49-minute npm backdoor turned Injective's wallet SDK into a seed-phrase stealer hiding as telemetry. https://intel.threadlinqs.com/threat/TL-2026-1381 #ThreatIntel #Injective #injectivelabs #npm
July 15, 2026 at 4:38 PM
⚠️ 3 days on and npm @injectivelabs/sdk-ts@1.20.21 is still installable. OSV-confirmed malware we flagged early. Don't pull it in.

#npm #malware #supplychainsecurity
Still live: npm @injectivelabs/sdk-ts@1.20.21
OSV-confirmed malware, still installable 3 days after PkgRadar flagged it.
pkgradar.com
July 13, 2026 at 7:35 PM
AI and supply chain attacks dominated today: Ghostcommit used image-based prompt injection, while a GitHub compromise at Injective Labs pushed wallet-stealing npm packages. Critical patches remain urgent. #Ghostcommit #InjectiveLabs #npm
Cybersecurity News | Daily Recap [11 Jul 2026]
Daily Recap, Two key themes dominated today: attackers are targeting AI and software supply chains, including Ghostcommit’s prompt-injection images and a GitHub compromise at Injective Labs that pushed wallet-key-stealing npm packages. Critical patching also remains urgent, with vulnerabilities in Zimbra, ShareFile, U-Boot, and Gitea along with broader pressure on healthcare, privacy, and enforcement efforts.
www.hendryadrian.com
July 12, 2026 at 3:45 PM
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemon…
#hackernews #news
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases. The compromised version, @injectivelabs/sdk-ts@1.20.21, came embedded with fake telemetry functionality that exfiltrated data from cryptocurrency wallets. The version was
thehackernews.com
July 12, 2026 at 3:03 AM
Compromised @injectivelabs/sdk-ts v1.20.21 hid code that stole BIP-39 mnemonics and private keys, disguised as telemetry and sent to a fake testnet endpoint. Fixed in v1.20.23. #Injective #BIP39 #PrivateKey
Not-so-anonymous telemetry: The @injectivelabs/sdk-ts backdoor
A compromised version 1.20.21 of @injectivelabs/sdk-ts was published with hidden code that stole BIP-39 mnemonic seed phrases and private keys by disguising the theft as SDK telemetry. The malicious behavior used a fake Injective testnet endpoint for exfiltration, was live for about 49 minutes, and was removed in version 1.20.23. #injectivelabs #sdk-ts #Injective #BIP39 #PrivateKey #GitHub
www.hendryadrian.com
July 11, 2026 at 6:45 AM
Injective Labs' SDK GitHub repo was compromised, and malicious npm package @injectivelabs/sdk-ts@1.20.21 was used to steal wallet private keys and seed phrases, affecting 17 related packages. #InjectiveLabs #npm #CryptoSecurity
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
Unknown threat actors compromised the Injective Labs SDK GitHub repository and published a malicious npm package, @injectivelabs/sdk-ts@1.20.21, to steal cryptocurrency wallet private keys and mnemonic seed phrases. The attack also spread to 17 related @injectivelabs packages, so users should treat any exposed keys as compromised and rotate them immediately. #InjectiveLabs #@injectivelabs/sdk-ts...
www.hendryadrian.com
July 10, 2026 at 9:45 PM
🤖 Injective Labs GitHub compromise pushed malicious npm packages stealing crypto wallet keys. Attackers published @injectivelabs/sdk-ts@1.20.21 with fake telemetry exfiltrating private keys and seed phrases.

https://thehackernews.com/2026/07/injective-labs-github-compromise-pushes.html
July 10, 2026 at 9:56 PM
Not-so-anonymous telemetry: The @injectivelabs/sdk-ts backdoor
Not-so-anonymous telemetry: The @injectivelabs/sdk-ts backdoor
securitylabs.datadoghq.com
July 10, 2026 at 9:44 AM
Injective SDK npm Compromise Exposes Wallet-Key Theft Risk Socket, Ox Security and StepSecurity said they detected wallet-stealing code in @injectivelabs/sdk-ts npm package version 1.20.21 after an Injective Labs contributor account was compromised. Cybersecurity Fintech Link card below.
Injective SDK npm Compromise Exposes Wallet-Key Theft Risk
Socket, Ox Security and StepSecurity said they detected wallet-stealing code in @injectivelabs/sdk-ts npm package version 1.20.21 after an Injective Labs contributor account was compromised. Socket said the malicious
stechtimes.com
July 10, 2026 at 6:07 AM