Skip to content
Injective Labs SDK Compromised in Supply Chain Attack

Injective Labs SDK Compromised in Supply Chain Attack

First seen 10 Jul 2026, 19:01 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 14:16 UTC
  • •Version 1.20.21 of the @injectivelabs/sdk-ts npm package was compromised to steal wallet credentials.
  • •The malicious package was downloaded over 300 times before being deprecated within 49 minutes.
  • •Injective Labs confirmed that no user funds were at risk during the incident.

On July 8, 2026, a supply chain attack targeted Injective Labs, compromising version 1.20.21 of the @injectivelabs/sdk-ts npm package. The attack exploited a legitimate developer's GitHub account, allowing attackers to inject malicious code designed to steal cryptocurrency wallet private keys and mnemonic seed phrases. The malicious package was downloaded over 300 times before being deprecated, affecting 18 related npm packages and potentially exposing 87 downstream dependent packages. Injective Labs confirmed that no user funds were compromised, and the malicious code was removed within approximately 49 minutes of detection. Security firms Socket and StepSecurity reported the incident, highlighting a growing trend of targeting developer tools rather than directly attacking blockchain infrastructure. Developers are advised to upgrade to the clean version 1.20.23 and rotate any credentials that may have been exposed.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-06-08
Suspicious commits detected
Suspicious activity began on the GitHub account of a trusted developer, indicating a potential compromise.
Kucoin
2026-07-08
Malicious package published
Version 1.20.21 of the @injectivelabs/sdk-ts package was published, containing malware to steal private keys.
Finance.Biggo
2026-07-08
Package deprecated
The malicious package was deprecated within approximately 49 minutes after detection by Injective Labs.
Bitget

More articles in this cluster (20)

Common questions

What should developers do if they downloaded the malicious package?
Developers should upgrade to version 1.20.23 or later and rotate any wallet credentials that may have been exposed.
How long was the malicious package available?
The malicious package was available for download for approximately 49 minutes before being deprecated.
Were any funds lost during this incident?
No, Injective Labs confirmed that no user funds were compromised during the attack.