logo

Compromised Injective SDK npm Package Exfiltrates Cryptocurrency Wallet Keys (Campaign)

ID: d8fb9162-0e9a-5303-aa53-a9c1d5ba156c

STIX ID: report--d8fb9162-0e9a-5303-aa53-a9c1d5ba156c

Feed Name: Wiz Cloud Threat Landscape

Threat Score
78/100

Date Published: 2026-07-09

Date Updated: 2026-07-19

Author: [email protected] (Wiz Threat Research)

...
...

A compromised maintainer account led to a malicious release of @injectivelabs/[email protected] that intercepted wallet mnemonics and private keys by altering `fromMnemonic` and `fromHex` functions; captured secrets were Base64-encoded and sent via HTTPS POST to an Injective-owned endpoint. The malicious SDK was published across 17 additional packages (directly or transitively depending on it), received ~310 downloads before deprecation, and could affect downstream projects that relied on the compromised version.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.