United States
USA
Attackers compromised a legitimate contributor account associated with the Injective Labs SDK repository and inserted malicious code into the official @injectivelabs/sdk-ts package. Version 1.20.21 was published on June 8, 2026 with code that intercepted wallet key-derivation operations and exfiltrated mnemonic phrases and private keys through disguised telemetry. Seventeen additional Injective-scoped packages were published with dependencies pinned to the compromised SDK, extending the software supply-chain exposure to downstream developers and applications. The malicious release was detected and reverted quickly, with approximately 310 downloads reported during the exposure window.
Estimated severity
73 / 100
Source reliability
90 / 100
Approximate Date
08/06/2026
Targeted Company
INJECTIVE LABS
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
United States
USA
No other affected countries reported
Target country
United States
Affected countries
Impacted regions
No information
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
No information
Please rotate your phone