A malicious release of the npm package @injectivelabs/sdk-ts (v1.20.21) was published in a software supply-chain attack that embedded infostealer functionality to capture cryptocurrency wallet private keys and mnemonic phrases. The tainted code was introduced through commits to Injective Labs’ official GitHub repository using a contributor account with prior project history, then shipped to npm, where it hooked wallet key-generation functions during normal library use, base64-encoded the captured secrets, and exfiltrated them in POST requests to an Injective Labs public infrastructure endpoint to blend with legitimate traffic.
The compromise extended beyond the core package through dependency poisoning: attackers published 17 additional @injectivelabs scoped packages pinned to the malicious SDK version, and reporting identified 87 dependent packages in scope with a combined 112,378 downloads. Although the malicious sdk-ts release was reportedly downloaded about 310 times before detection and rollback, the compromised npm version and GitHub release artifacts remained available at the time of reporting. Developers were urged to upgrade to 1.20.23, audit direct and transitive @injectivelabs dependencies, and treat any mnemonic phrases or private keys processed by affected versions as compromised.

Trace attribution and downstream blast radius.
8 events from the most recent confirmed update back to the earliest known activity.
SlowMist reported that the malicious code in @injectivelabs/sdk-ts v1.20.21 was embedded in wallet key derivation functions and triggered by generate(), fromMnemonic(), and string-based fromHex() calls. The stolen secrets were Base64-encoded and sent in the X-Request-Id header of empty HTTP POST requests disguised as gRPC-Web traffic to an Injective-domain hostname.
Reporting on the supply-chain attack said 17 additional @injectivelabs scoped packages were configured to depend on the compromised @injectivelabs/sdk-ts@1.20.21 release, expanding downstream exposure through transitive dependencies. This quantified the breadth of package propagation beyond the initially disclosed malicious SDK package.
Researchers said the supply-chain attack occurred after attackers gained access to a legitimate contributor's GitHub account and used the normal release workflow to publish the compromised @injectivelabs/sdk-ts package. This added new technical detail about how the malicious npm release was introduced.
The @injectivelabs/sdk-ts compromise was publicly reported in GitHub issue #697. This marked a public disclosure of the incident separate from the malicious publication, revert, and clean package release.
A clean version of the package, 1.20.23, was published shortly after the malicious release was reverted. Developers were advised to upgrade and treat any keys or mnemonic phrases processed by affected versions as compromised.
The malicious activity was detected and reverted quickly on the night it began. This rapid response appears to have limited impact, with the compromised npm version reportedly downloaded 310 times.
A malicious version of @injectivelabs/sdk-ts (v1.20.21) was published to npm as part of a supply-chain attack. The attacker also caused additional @injectivelabs packages to depend on the compromised version, expanding exposure across the ecosystem.
Malicious activity involving the npm package @injectivelabs/sdk-ts version 1.20.21 began on June 8, 2026. The compromised package contained code that captured wallet private keys and mnemonic phrases and exfiltrated them to an InjectiveLabs public infrastructure endpoint.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
9 references tracked. Mallory keeps watching after this page renders.
slowmist.medium.com
Open sourcecysecurity.news
Open sourcethehackernews.com
Open sourcecysecurity.news
Open sourceox.security
Open sourcethreats.wiz.io
Open sourcesocket.dev
Open sourcesecuritylabs.datadoghq.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.