Compromised Injective SDK npm Release Exfiltrates Wallet Keys and Mnemonics

· Original article ↗

Summary

Malicious Injective SDK version 1.20.21 and 17 related packages exfiltrated wallet keys and mnemonic phrases during use. The release was deprecated but remained downloadable; developers were advised to upgrade and rotate exposed credentials.

Key points

  • The malicious @injectivelabs/sdk-ts@1.20.21 release was published to npm after malicious commits appeared in the project’s GitHub repository through a developer account.
  • When wallet key-generation functions ran, the package recorded mnemonic phrases or private-key material and sent it in a POST request to an Injective-related endpoint.
  • The malicious version was also pinned by 17 other @injectivelabs packages, exposing users through direct or transitive dependencies.
  • The package had about 50,000 weekly downloads; the article reported 310 downloads of the malicious version.
  • A clean version was published, but version 1.20.21 was deprecated rather than removed from npm, and compromised release artifacts remained on GitHub at the time of reporting.
  • Developers were advised to check direct and transitive dependencies, upgrade to clean version 1.20.23, and treat any keys or mnemonics used with the packages as compromised and rotate them.

Article Details

Victim Organization
Injective Labs
Incident Type
Software supply-chain compromise involving malicious npm releases that capture and exfiltrate wallet private keys and mnemonic phrases
Incident Date
2026-06-08
Data Types Exposed
  • Wallet mnemonic phrases passed to fromMnemonic
  • Private-key material or its representation passed to fromHex
  • Key-derivation method markers
Affected Records
Not disclosed
Affected Data Size
Not disclosed
Operational Impact
The attacker published malicious @injectivelabs/sdk-ts version 1.20.21 and versions of 17 additional scoped packages pinned directly or transitively to it. Official npm statistics cited by the source showed 310 downloads of the malicious SDK version; this is not a confirmed victim count. On 2026-06-08, suspicious commits began at 20:06 GMT+2, the malicious release was published at 22:59 GMT+2, a reverting commit was submitted at 23:18 GMT+2, and a clean version was published at 23:48 GMT+2. At writing, the malicious npm version was deprecated but remained downloadable, and compromised release artifacts remained on GitHub. The source did not establish actual wallet losses or the number of users whose secrets were stolen.
Ransom Or Extortion
Not disclosed
Claim Status
confirmed

Indicators of compromise

TypeIndicatorContext
SHA256103c4e6181151c1bcfedc41506cd1815458c38375d08a8fcd9981dbe0b965ce0Source-listed SHA-256 indicator for /dist/cjs/accounts-Cy0p4lLW.cjs, containing the infostealer functionality.
SHA2569a59eb454f3ca3fe91214136ee5edd417cc47a80e6f169b52099d6561944baf9Source-listed SHA-256 indicator for /dist/esm/accounts-jQ1GSgaW.js, containing the infostealer functionality.
URLhxxps[:]//testnet[.]archival[.]chain[.]grpc-web[.]injective[.]networkInjectiveLabs public infrastructure endpoint explicitly identified as the destination for POST requests exfiltrating base64-encoded wallet secrets; attacker control of the endpoint is not established.

MITRE ATT&CK

Vendors

Products

Industries

Related Articles