Threats · 66 days ago
Pinned transitive packages widened this from one bad release into a broader wallet theft risk. Teams that only check top-level installs can miss the malicious code, because the poisoned version was copied into 17 scoped packages tied to the same release.
The malicious @injectivelabs/sdk-ts 1.20.21 release was published to npm with fake telemetry that actually read and exfiltrated wallet private keys and mnemonic phrases. Socket says the package gets about 50,000 weekly downloads, and the same version was pushed across 17 @injectivelabs scoped packages, extending exposure to transitive users who never installed the SDK directly.
The practical break is trust in pinned npm dependencies: the version number that should narrow exposure became the path that spread it. Even after the clean release, the malicious artifacts and deprecated package status left enough residue that teams need to treat affected wallet secrets as exposed.
4 sources covering this story
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
Unknown attackers compromised Injective Labs' GitHub repo to publish npm package 1.20.21, which steals wallet private keys and seed phrases.
Injective SDK on npm infected with cryptocurrency wallet stealer
Hackers compromised the Injective Labs SDK project's GitHub repository and used it to publish a malicious package on the Node Package Manager (npm) that stole cryptocurrency wallet private keys and mnemonic seed phrases.
Compromised Injective SDK npm Package Exfiltrates Wallet Key...
Compromised Injective SDK npm version 1.20.21 exfiltrates wallet private keys and mnemonics through fake telemetry functionality.
Not-so-anonymous telemetry: The @injectivelabs/sdk-ts backdoor | Datadog Security Labs
A malicious commit disguised as SDK telemetry briefly compromised @injectivelabs/sdk-ts, exfiltrating wallet mnemonics and private keys.
Part of the PlainSec briefing for 2026-07-10