MIT TRACE

MIT CTL Logo
Back to Main Dashboard

Compromised Injective Labs SDK distributes wallet-key stealing code

Attackers compromised a legitimate contributor account associated with the Injective Labs SDK repository and inserted malicious code into the official @injectivelabs/sdk-ts package. Version 1.20.21 was published on June 8, 2026 with code that intercepted wallet key-derivation operations and exfiltrated mnemonic phrases and private keys through disguised telemetry. Seventeen additional Injective-scoped packages were published with dependencies pinned to the compromised SDK, extending the software supply-chain exposure to downstream developers and applications. The malicious release was detected and reverted quickly, with approximately 310 downloads reported during the exposure window.

73

Estimated severity

73 / 100

90

Source reliability

90 / 100

Approximate Date

08/06/2026

Targeted Company

INJECTIVE LABS

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

United States

USA

Other Affected Countries

No other affected countries reported

Target country

United States

Affected countries

United States

Impacted regions

No information

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Supply chain data integrity impact

Affected sectors

Technology & IT ServicesFinance & Insurance

Affected departments

Information TechnologyEngineering & Maintenance

Attack Profile

Attack types

Software supply chain compromiseMalwareData exfiltrationUnauthorized access

Attributed threat actors

No information

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.