Skip to main content
Sign in

Injective (npm SDK supply-chain attack)

avoid.net/injective-npm-sdk-supply-chain-attack62/100·75% conf.
[VERIFIED]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·63749b…WT8p

Summary

On July 8, 2026, a compromised maintainer GitHub account was used to publish a backdoored version of @injectivelabs/sdk-ts and 17 related npm packages, disguising a wallet-key-stealing payload as SDK usage telemetry. The malicious code was live for approximately 49 minutes before being reverted; Injective Labs stated no funds on the network were at risk and no user losses were confirmed. This incident is a software supply-chain compromise affecting an official npm SDK maintained by Injective Labs — it did not involve a vulnerability or exploit of the Injective blockchain protocol itself.

Have evidence about Injective (npm SDK supply-chain attack)?
0
Accepted
1
Under review
0
Rejected / revoked

Community submissions

Timeline(5 events)

8 July 2026

Malicious commit adding the wallet-key-exfiltration payload, disguised as SDK usage-analytics telemetry, is pushed directly to the master branch of @injectivelabs/sdk-ts using a compromised maintainer account (approx. 20:24 UTC).

StepSecurity

8 July 2026

A version bump triggers automated CI publishing of version 1.20.21, which propagates the backdoor to 18 @injectivelabs-scoped npm packages within minutes (approx. 20:54–21:00 UTC).

StepSecurity

8 July 2026

A revert commit removes the malicious payload from the repository (approx. 21:16 UTC).

StepSecurity

8 July 2026

Clean version 1.20.23 is published across all 18 affected packages and version 1.20.21 is deprecated on the npm registry, ending the exposure window at roughly 49 minutes (approx. 21:47–21:49 UTC).

StepSecurity

9 July 2026

Security researchers and outlets including Socket, Ox Security, The Hacker News, and Bleeping Computer publish analyses of the attack; Injective Labs CEO Eric Chen states no network funds are at risk.

CryptoBriefing
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (3 events). 6 of 6 cited source URLs have an Internet Archive snapshot.

model: claude-code-investigator

generated: 7/22/2026, 1:50:11 AM

last updated: 8/27/2026, 6:05:37 AM

3 views

avoid.net — verified advice for a post-truth world