Injective (npm SDK supply-chain attack)
Summary
On July 8, 2026, a compromised maintainer GitHub account was used to publish a backdoored version of @injectivelabs/sdk-ts and 17 related npm packages, disguising a wallet-key-stealing payload as SDK usage telemetry. The malicious code was live for approximately 49 minutes before being reverted; Injective Labs stated no funds on the network were at risk and no user losses were confirmed. This incident is a software supply-chain compromise affecting an official npm SDK maintained by Injective Labs — it did not involve a vulnerability or exploit of the Injective blockchain protocol itself.
Connected Entities
1 entities · 10 linked investigationsTimeline(5 events)
2026-07-08
Malicious commit adding the wallet-key-exfiltration payload, disguised as SDK usage-analytics telemetry, is pushed directly to the master branch of @injectivelabs/sdk-ts using a compromised maintainer account (approx. 20:24 UTC).
StepSecurity2026-07-08
A version bump triggers automated CI publishing of version 1.20.21, which propagates the backdoor to 18 @injectivelabs-scoped npm packages within minutes (approx. 20:54–21:00 UTC).
StepSecurity2026-07-08
A revert commit removes the malicious payload from the repository (approx. 21:16 UTC).
StepSecurity2026-07-08
Clean version 1.20.23 is published across all 18 affected packages and version 1.20.21 is deprecated on the npm registry, ending the exposure window at roughly 49 minutes (approx. 21:47–21:49 UTC).
StepSecurity2026-07-09
Security researchers and outlets including Socket, Ox Security, The Hacker News, and Bleeping Computer publish analyses of the attack; Injective Labs CEO Eric Chen states no network funds are at risk.
CryptoBriefingDecision Log
- #1publish⛓ pending7/22/2026, 1:53:39 AMhash: FZBVgLvR6ZxfzPfehfy4CaVbnaU3FqzGvYcaZzjftSYP
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-code-investigator
generated: 7/22/2026, 1:50:11 AM
last updated: 7/22/2026, 1:53:39 AM
avoid.net — verified advice for a post-truth world