Injective Labs SDK project GitHub repository hit by network compromise
Incident
Summary
Hide ▲
Show ▼
The Injective Labs SDK project suffered a GitHub repository compromise that let attackers publish a malicious @injectivelabs/sdk-ts v1.20.21 package, putting developers' wallet secrets at risk. The compromised release was tied to suspicious activity on June 8 and could steal private keys and mnemonic seed phrases from systems that used the SDK. A clean v1.20.23 release followed, but the malicious package had already been downloaded 310 times before deprecation.
Related Happenings
Jscrambler hit by network compromise
Incident
H score15
First: 13.07.2026 22:44
Last: 13.07.2026 22:44
Sources 1
About this happening:
The Jscrambler npm package suffered an unauthorized publication of a malicious version that exposed developers to infostealer theft risk. The bad release stayed li...
Jscrambler hit by network compromise
IncidentAbout this happening: The Jscrambler npm package suffered an unauthorized publication of a malicious version that exposed developers to infostealer theft risk. The bad release stayed li...
@Injectivelabs/[email protected] wallet-stealing package
Malware Activity
H score30
First: 10.07.2026 20:29
Last: 10.07.2026 20:29
Sources 1
How related:
Specifically, the poisoned version has been found to modify legitimate functions used in workflows to generate private keys by invoking a "trackKeyDerivation()" function under the guise of collecting anonymized usage metrics for SDK optimization.
About this happening:
The malicious @injectivelabs/[email protected] package is a wallet-stealing malware activity that can expose private keys and mnemonic seed phrases when library functions...
@Injectivelabs/[email protected] wallet-stealing package
Malware ActivityHow related: Specifically, the poisoned version has been found to modify legitimate functions used in workflows to generate private keys by invoking a "trackKeyDerivation()" function under the guise of collecting anonymized usage metrics for SDK optimization.
About this happening: The malicious @injectivelabs/[email protected] package is a wallet-stealing malware activity that can expose private keys and mnemonic seed phrases when library functions...
Sapphire Sleet Mastra npm supply-chain campaign
Campaign
H score42
First: 20.06.2026 17:09
Last: 20.06.2026 17:09
Sources 1
About this happening:
The Mastra AI supply-chain campaign was attributed to Sapphire Sleet / BlueNoroff after Microsoft said the operation compromised the npm maintainer account "ehindero...
Sapphire Sleet Mastra npm supply-chain campaign
CampaignAbout this happening: The Mastra AI supply-chain campaign was attributed to Sapphire Sleet / BlueNoroff after Microsoft said the operation compromised the npm maintainer account "ehindero...
Mastra @mastra/* npm packages hit by network compromise
Incident
H score47
First: 17.06.2026 10:38
Last: 17.06.2026 10:38
Sources 1
About this happening:
Mastra @mastra/* npm packages were compromised in a software supply chain attack that spread through the namespace on 2026-06-17. Microsoft now attributes the acti...
Mastra @mastra/* npm packages hit by network compromise
IncidentAbout this happening: Mastra @mastra/* npm packages were compromised in a software supply chain attack that spread through the namespace on 2026-06-17. Microsoft now attributes the acti...
Latest development: 20.06.2026 17:09
Microsoft attributed the Mastra AI supply chain attack to Sapphire Sleet, also known as BlueNoroff, and said the attackers compromised the npm maintainer account ehindero, which had publishing privileges across the Mastra package environment. The June 19 update said more than 140 packages in the @mastra scope were modified to inject easy-day-js.
Easy-day-js Mastra package-publishing campaign
Campaign
H score30
First: 17.06.2026 10:38
Last: 17.06.2026 10:38
Sources 1
About this happening:
The easy-day-js campaign mass-published more than 140 malicious npm packages across the @mastra/* namespace, creating broad supply-chain exposure for developers and bu...
Easy-day-js Mastra package-publishing campaign
CampaignAbout this happening: The easy-day-js campaign mass-published more than 140 malicious npm packages across the @mastra/* namespace, creating broad supply-chain exposure for developers and bu...
Timeline
-
09.07.2026 23:10 2 articles · 13d ago
Compromised contributor account publishes malicious @injectivelabs/sdk-ts v1.20.21
Untyped PhaseA GitHub account belonging to a legitimate Injective Labs contributor was compromised, first suspicious commits appeared on June 8, and @injectivelabs/sdk-ts v1.20.21 was published shortly afterward on npm with code that stole cryptocurrency wallet private keys and mnemonic seed phrases.
Show sources
- Injective SDK on npm infected with cryptocurrency wallet stealer — www.bleepingcomputer.com — 09.07.2026 23:10
- Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages — thehackernews.com — 10.07.2026 20:29
-
09.07.2026 23:10 2 articles · 13d ago
Security companies detect wallet-stealing @injectivelabs/sdk-ts supply-chain attack
Initial DisclosureSocket, Ox Security, and StepSecurity detected the supply-chain attack in @injectivelabs/sdk-ts v1.20.21 on July 9, 2026, reporting that the malicious package stole cryptocurrency wallet private keys and mnemonic seed phrases, was downloaded 310 times before deprecation, and was followed by a clean 1.20.23 release after the compromise was reverted.
Show sources
- Injective SDK on npm infected with cryptocurrency wallet stealer — www.bleepingcomputer.com — 09.07.2026 23:10
- Injective SDK on npm infected with cryptocurrency wallet stealer — www.bleepingcomputer.com — 09.07.2026 23:10