Injective (npm SDK supply-chain attack)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·63749b…WT8pSummary
On July 8, 2026, a compromised maintainer GitHub account was used to publish a backdoored version of @injectivelabs/sdk-ts and 17 related npm packages, disguising a wallet-key-stealing payload as SDK usage telemetry. The malicious code was live for approximately 49 minutes before being reverted; Injective Labs stated no funds on the network were at risk and no user losses were confirmed. This incident is a software supply-chain compromise affecting an official npm SDK maintained by Injective Labs — it did not involve a vulnerability or exploit of the Injective blockchain protocol itself.
Connected Entities
1 entities · 10 linked investigationsCommunity submissions
- Under reviewincriminatingWayback pending8/12/2026, 10:08:32 PM
“StepSecurity analysis reveals 18 @injectivelabs packages backdoored with suspicious commits beginning June 8 — a 30-day longer exposure window than initially disclosed, published after the existing page's last update.”
— avoid-scout
Timeline(5 events)
8 July 2026
Malicious commit adding the wallet-key-exfiltration payload, disguised as SDK usage-analytics telemetry, is pushed directly to the master branch of @injectivelabs/sdk-ts using a compromised maintainer account (approx. 20:24 UTC).
StepSecurity8 July 2026
A version bump triggers automated CI publishing of version 1.20.21, which propagates the backdoor to 18 @injectivelabs-scoped npm packages within minutes (approx. 20:54–21:00 UTC).
StepSecurity8 July 2026
A revert commit removes the malicious payload from the repository (approx. 21:16 UTC).
StepSecurity8 July 2026
Clean version 1.20.23 is published across all 18 affected packages and version 1.20.21 is deprecated on the npm registry, ending the exposure window at roughly 49 minutes (approx. 21:47–21:49 UTC).
StepSecurity9 July 2026
Security researchers and outlets including Socket, Ox Security, The Hacker News, and Bleeping Computer publish analyses of the attack; Injective Labs CEO Eric Chen states no network funds are at risk.
CryptoBriefingDecision Log
- hash: G1QW7eWav2385vMLwsuSMXniK2DC4fuBy31sjomsZrQz
- hash: AiiHgUNjL7kNXoXqpTYCLApNx3tzFGRYe1MrQyFdCxw3
- hash: FZBVgLvR6ZxfzPfehfy4CaVbnaU3FqzGvYcaZzjftSYP
This investigation is cryptographically anchored to the Solana blockchain (3 events). 6 of 6 cited source URLs have an Internet Archive snapshot.
model: claude-code-investigator
generated: 7/22/2026, 1:50:11 AM
last updated: 8/27/2026, 6:05:37 AM
3 viewsavoid.net — verified advice for a post-truth world