Injective npm package hack exposes wallet keys
A compromised Injective npm package stole wallet keys and mnemonics, impacting 300+ downloads and 17+ related packages before a quick patch.
A popular Injective npm package, @injectivelabs/sdk-ts, suffered a supply chain attack after a developer’s GitHub account was compromised. Hackers injected malicious code into version 1.20.21, which secretly captured wallet private keys and mnemonic phrases during wallet operations. The stolen data was sent to an attacker-controlled server disguised as legitimate Injective infrastructure. The attack extended beyond the main SDK, affecting 17–18 related packages within the Injective Labs npm scope. This put users at risk even if they hadn’t directly installed the compromised SDK. The malicious version was downloaded over 300 times before being removed, and a clean version was published within about an hour. Security researchers described the attack as sophisticated, with a payload that activated at runtime and evaded standard scanners. Although the malicious code has been removed and the affected version deprecated, experts warn that any keys or mnemonics processed through the compromised packages should be considered at risk, and the threat may not be fully contained.