Skip to main content
Sign in

Injective (npm SDK supply-chain attack)

avoid.net/injective-npm-sdk-supply-chain-attack62/100·75% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Summary

On July 8, 2026, a compromised maintainer GitHub account was used to publish a backdoored version of @injectivelabs/sdk-ts and 17 related npm packages, disguising a wallet-key-stealing payload as SDK usage telemetry. The malicious code was live for approximately 49 minutes before being reverted; Injective Labs stated no funds on the network were at risk and no user losses were confirmed. This incident is a software supply-chain compromise affecting an official npm SDK maintained by Injective Labs — it did not involve a vulnerability or exploit of the Injective blockchain protocol itself.

Have evidence about Injective (npm SDK supply-chain attack)?

Timeline(5 events)

2026-07-08

Malicious commit adding the wallet-key-exfiltration payload, disguised as SDK usage-analytics telemetry, is pushed directly to the master branch of @injectivelabs/sdk-ts using a compromised maintainer account (approx. 20:24 UTC).

StepSecurity

2026-07-08

A version bump triggers automated CI publishing of version 1.20.21, which propagates the backdoor to 18 @injectivelabs-scoped npm packages within minutes (approx. 20:54–21:00 UTC).

StepSecurity

2026-07-08

A revert commit removes the malicious payload from the repository (approx. 21:16 UTC).

StepSecurity

2026-07-08

Clean version 1.20.23 is published across all 18 affected packages and version 1.20.21 is deprecated on the npm registry, ending the exposure window at roughly 49 minutes (approx. 21:47–21:49 UTC).

StepSecurity

2026-07-09

Security researchers and outlets including Socket, Ox Security, The Hacker News, and Bleeping Computer publish analyses of the attack; Injective Labs CEO Eric Chen states no network funds are at risk.

CryptoBriefing
Provenance & Audit Trail

Decision Log

  • #1publish⛓ pending7/22/2026, 1:53:39 AM
    hash: FZBVgLvR6ZxfzPfehfy4CaVbnaU3FqzGvYcaZzjftSYP

This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.

model: claude-code-investigator

generated: 7/22/2026, 1:50:11 AM

last updated: 7/22/2026, 1:53:39 AM

avoid.net — verified advice for a post-truth world