
Security researchers said a backdoored Injective SDK release briefly reached npm and spread across 18 related packages, while Injective later said the affected versions were deprecated and no users were at risk.
Security researchers StepSecurity and Socket said a malicious version of Injective’s TypeScript SDK was briefly published to npm on July 8, 2026 through a compromised GitHub maintainer account, creating a software supply chain attack aimed at seed phrases and private keys during wallet operations. They said version 1.20.21 of @injectivelabs/sdk-ts was downloaded 310 times and pinned across 18 associated npm packages before removal, with clean replacements published within roughly 49 minutes of the initial malicious push. Injective later said the issue was resolved immediately, the affected versions were deprecated and replaced, and there were no user fund losses or risk to users; this conflicts with the researchers’ reported download count and exposure window. No widespread theft has been confirmed, but developers who installed version 1.20.21 or cached it in CI/CD systems were urged by researchers to review their environments and treat wallet operations performed with the affected code as potentially compromised.