Injective Labs GitHub Hack: How Malicious npm Packages Stole Crypto Wallet Keys (2026)

The recent Injective Labs GitHub compromise has sent shockwaves through the cryptocurrency community, highlighting the vulnerabilities within software supply chains. This incident underscores the critical need for robust security measures in the development and distribution of open-source software. The attack, carried out by unknown threat actors, exploited the Injective Labs SDK project's GitHub repository to publish a malicious npm package, '@injectivelabs/sdk-ts@1.20.21', designed to steal cryptocurrency wallet private keys and mnemonic seed phrases. This package, released on July 8, 2026, was a cunningly disguised malware, leveraging a fake telemetry function to exfiltrate data from unsuspecting cryptocurrency wallets.

The malware's simplicity and stealth are particularly concerning. By integrating itself into legitimate functions used in workflows to generate private keys, it triggered when an unsuspecting developer used the library. The threat actors cleverly disguised the malicious function as a telemetry tool for SDK optimization, collecting anonymized usage metrics. However, the captured data, including a hard-coded marker and sensitive information, was sufficient for the actors to regenerate private keys.

This attack extended beyond the initial package, as the threat actors also published version 1.20.21 across 17 additional '@injectivelabs' scoped packages, potentially affecting transitive users. These packages, including '@injectivelabs/utils' and '@injectivelabs/wallet-base', were compromised, posing a significant risk to any developers or applications that depended on them. The malware's ability to steal crypto wallet keys and mnemonic phrases, the master keys for any crypto wallet, is a severe threat to the security of cryptocurrency users.

The exfiltration mechanism, designed to reduce outbound requests, further underscores the sophistication of the attack. It appends multiple key derivations over a two-second window into a single queue and sends them in a single HTTPS POST request to an external server. This method, while effective in minimizing detection, highlights the importance of comprehensive security audits and the need for developers to remain vigilant against supply chain attacks.

The compromise of the Injective Labs GitHub repository was facilitated through the repository's trusted-publisher (OIDC) pipeline, with malicious commits authored and pushed under the identity of an existing, trusted maintainer. This attack serves as a stark reminder of the potential risks associated with open-source software and the importance of maintaining a robust security posture throughout the software development lifecycle.

In response to the attack, users are advised to update to the clean version of the package (1.20.23), treat any private key or mnemonic phrase passed through the package as compromised, and rotate them. Additionally, checking for transitive dependencies is crucial to ensure that the attack has not affected other parts of the software ecosystem. This incident underscores the need for enhanced security practices in the open-source community, including rigorous code reviews, comprehensive testing, and the adoption of secure development practices to safeguard against future attacks.

Injective Labs GitHub Hack: How Malicious npm Packages Stole Crypto Wallet Keys (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Msgr. Refugio Daniel

Last Updated:

Views: 5367

Rating: 4.3 / 5 (74 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Msgr. Refugio Daniel

Birthday: 1999-09-15

Address: 8416 Beatty Center, Derekfort, VA 72092-0500

Phone: +6838967160603

Job: Mining Executive

Hobby: Woodworking, Knitting, Fishing, Coffee roasting, Kayaking, Horseback riding, Kite flying

Introduction: My name is Msgr. Refugio Daniel, I am a fine, precious, encouraging, calm, glamorous, vivacious, friendly person who loves writing and wants to share my knowledge and understanding with you.