logo

Injective SDK on npm infected with cryptocurrency wallet stealer

ID: 428182bd-5bd9-5286-874e-39ed7fb10c7e

STIX ID: report--428182bd-5bd9-5286-874e-39ed7fb10c7e

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-07-09

Date Updated: 2026-07-19

Author: Bill Toulas

...
...

A malicious release (v1.20.21) of the @injectivelabs/sdk-ts npm package — published after a GitHub contributor account was compromised — contained code that captured wallet mnemonics and private keys when SDK wallet-generation/import functions were called, encoded them in base64, and exfiltrated them via HTTP POST to an Injective Labs infrastructure endpoint; the malicious package was downloaded at least 310 times and 17 related packages were pinned to the compromised version, potentially affecting a broad set of developers and dependent projects.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.