Supply-chain attack backdoors Injective npm package

Attackers modified Injective npm package v1.20.21 to capture wallet private keys and mnemonics; the malicious release came from a compromised GitHub account and was downloaded about 310 times.

Security firm Socket found that version 1.20.21 of the @injectivelabs/sdk-ts npm package was altered to hook wallet key-derivation routines. Suspicious commits began on June 8 and the tainted release was pushed from a compromised developer GitHub account. The package was downloaded about 310 times and was pinned across 17 other packages in the Injective Labs npm scope, which could expose users who did not install the SDK directly.

The injected code intercepted normal key-generation functions, copied private keys and seed phrases, encoded the harvested data and transmitted it to a web address designed to resemble an Injective network endpoint. The payload used fake telemetry to send the stolen material when an application invoked affected functions.

Socket removed the malicious code and warned, “Any keys or mnemonics passed through affected packages should be treated as compromised.” The firm added that the campaign was not fully contained at the time of its disclosure.

Injective’s CEO Eric Chen wrote that the issue is fixed, the affected npm versions are deprecated and no funds on the network are at risk. Socket did not confirm whether any wallets or funds were actually stolen in connection with the compromised package.

Security specialists classify the incident as a software supply chain attack, where attackers target developer tools on platforms such as GitHub and npm to reach wallets and applications. Similar campaigns targeting developer packages have been detected in recent months, and some breaches of developer platforms have been reported.

Industry data shows wallet compromises were the most costly attack type in the first half of 2026; security firm CertiK estimated $444 million stolen across 33 incidents. GitHub reported unauthorized access to some internal repositories on May 20 after an employee device was compromised.

Developers and applications that processed Injective wallet workflows and anyone who relied on the affected releases should assume keys and seed phrases passed through those packages are exposed and replace them. The malicious code has been removed from the npm package.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author