NPM · JULY 2026 · CONFIRMED

Injective npm Package Compromised: Wallet Keys and Mnemonics Stolen

Severity: CRITICAL

The Injective npm package was compromised, leading to the exfiltration of wallet recovery phrases and private keys. Applications using affected versions are at risk.

What happened

The Injective npm package, specifically version 1.20.21 of @injectivelabs/sdk-ts, was compromised through a hijacked maintainer account. This version, released on July 8, 2026, contained a backdoor that exfiltrated wallet recovery phrases and private keys to an attacker-controlled server. The malicious functionality was introduced via commits from a developer with an established contribution history to the repository. Applications that installed this version or any of the 17 scoped packages pinned to it are affected.

The compromised package was detected by multiple security firms, including Socket, Ox Security, and StepSecurity. The malicious code was embedded as fake telemetry functionality within the package. Despite the package being deprecated on the npm registry, the release artifacts are still available for download from GitHub.

If your application installed any of the affected packages during the compromised window, it is recommended to treat any wallet secrets it touched as exposed and rotate them immediately. Consult the primary sources for detailed indicators of compromise and defensive guidance.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If injective is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats