# Injective Labs npm package compromised, malicious version downloaded

**Published:** 2026-07-18T01:09:47.806Z  
**Topic:** Injective  
**Sentiment:** neutral  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/cd68d6a6-e2ca-467b-83bc-a8d4ab5f9012

Injective Labs supply‑chain breach exposed a malicious @injectivelabs/sdk‑ts 1.20.21 npm release that stole wallet keys; 310 downloads reported, zero confirmed

A malicious version of the @injectivelabs/sdk‑ts npm package (v1.20.21) was published after a GitHub compromise, and security firm Socket says it was downloaded 310 times before removal, prompting urgent key‑rotation warnings for developers [1].

| At a glance | |
|---|---|
| Package version | @injectivelabs/sdk‑ts v1.20.21 |
| Weekly downloads (legitimate) | ~50,000 |
| Reported malicious downloads | 310 |
| Catalyst | GitHub repo breach and malicious commit on June 8 |

## How the attack unfolded  
Threat actors gained access to the official Injective Labs GitHub repository and pushed a poisoned release of the SDK package on July 9, 2026. The malicious code hijacked wallet‑key‑derivation functions, captured private keys and seed phrases, and exfiltrated them via a forged telemetry request that mimicked an Injective network server [1][3]. Because the SDK is a core dependency for many downstream packages, the compromise spread across 17 related packages in the Injective Labs scope, potentially affecting developers who never installed the SDK directly [1].

## Impact and response  
Socket reported that the compromised package was downloaded 310 times before it was removed, while Injective Labs publicly stated that “zero downloads” occurred and that the issue was patched immediately [1]. No on‑chain theft has been confirmed, and the project’s CEO emphasized that no funds on the Injective network are at risk [1]. Nonetheless, the incident highlights the growing threat of software supply‑chain attacks, which the Security Alliance noted as the most costly vector in H1 2026, with $444 million stolen across 33 incidents [1].

## What to watch
- Monitor npm for any re‑appearance of version 1.20.21 or related packages in the @injectivelabs scope.  
- Watch for announcements from Injective Labs regarding additional remediation steps or audit results.  
- Track developer‑focused security advisories for supply‑chain hardening measures, such as enforced lockfiles and integrity checks.  

The breach underscores that even well‑maintained open‑source SDKs can become attack vectors, forcing developers to treat any keys or mnemonics processed through compromised packages as compromised and to rotate credentials promptly.

## Sources
1. Cointelegraph — [Hackers tried to backdoor Injective NPM package to steal wallet keys](https://cointelegraph.com/news/hackers-compromise-injective-npm-package-with-malware-to-steal-wallet-keys)
2. Zxcloudsecurity — [Injective Labs npm Supply Chain Attack Steals Crypto Keys](https://zxcloudsecurity.co.uk/posts/injective-labs-github-npm-supply-chain-attack-crypto-wallet-key-theft/)
3. Cyber — [Injective Labs SDK on npm Hijacked in... - CyberNetSec.io](https://cyber.netsecops.io/articles/injective-labs-sdk-npm-hijacked-in-crypto-stealing-supply-chain-attack/)

---
Cite as: TrendWatcher, "Injective Labs npm package compromised, malicious version downloaded", https://www.trendwatcher.in/article/cd68d6a6-e2ca-467b-83bc-a8d4ab5f9012
