GitHub Compromise: Injective Labs Steals Crypto Wallet Keys via npm Packages (2026)

The recent Injective Labs GitHub compromise has exposed a critical vulnerability in the software supply chain, highlighting the dangers of malicious npm packages. This incident underscores the importance of vigilance and proactive security measures in the ever-evolving landscape of cybersecurity.

The attack involved a sophisticated manipulation of the Injective Labs SDK project's GitHub repository, where a malicious package was published on the npm registry. This package, @injectivelabs/sdk-ts@1.20.21, was designed to steal cryptocurrency wallet private keys and mnemonic seed phrases, posing a significant threat to users' digital assets.

What makes this attack particularly insidious is the use of a seemingly innocuous telemetry function. The poisoned version of the package modifies legitimate functions used in workflows to generate private keys, invoking a 'trackKeyDerivation()' function under the guise of collecting anonymized usage metrics for SDK optimization. This function, however, serves a hidden purpose.

The malware within the package is designed to trigger when the library functionality is used by an unsuspecting developer. By avoiding lifecycle scripts and not launching it during the installation phase, the malware remains hidden. It captures sensitive information, including the hard-coded marker describing the method used to generate the private key and the actual sensitive information needed for generating the private key.

The threat actor behind the attack published version 1.20.21 across 17 additional @injectivelabs scoped packages, putting transitive users at risk. These packages, such as @injectivelabs/utils and @injectivelabs/wallet-base, were compromised and pinned the malicious SDK version, potentially affecting a wide range of applications.

The malware's exfiltration mechanism is designed to reduce the number of outbound requests by appending multiple key derivations over a two-second window into a single queue and then sending them in the form of an HTTPS POST request to an external server. This sophisticated approach makes it harder to detect the malicious activity.

The attack was facilitated through the repository's own trusted-publisher (OIDC) pipeline, with malicious commits authored and pushed under the identity of an existing, trusted maintainer. This level of sophistication highlights the need for robust identity verification and access control measures.

In response to the attack, users are advised to update to the newly published, clean version of the package (1.20.23). Any private key or mnemonic phrase passed through the package should be treated as compromised and rotated. Additionally, users should check for transitive dependencies to ensure a comprehensive security audit.

This incident serves as a stark reminder of the importance of software supply chain security. It highlights the need for continuous monitoring, proactive threat detection, and robust identity verification measures to safeguard against such attacks. As the cybersecurity landscape continues to evolve, organizations must remain vigilant and adaptable to protect their digital assets and users' sensitive information.

GitHub Compromise: Injective Labs Steals Crypto Wallet Keys via npm Packages (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Sen. Emmett Berge

Last Updated:

Views: 5855

Rating: 5 / 5 (60 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Sen. Emmett Berge

Birthday: 1993-06-17

Address: 787 Elvis Divide, Port Brice, OH 24507-6802

Phone: +9779049645255

Job: Senior Healthcare Specialist

Hobby: Cycling, Model building, Kitesurfing, Origami, Lapidary, Dance, Basketball

Introduction: My name is Sen. Emmett Berge, I am a funny, vast, charming, courageous, enthusiastic, jolly, famous person who loves writing and wants to share my knowledge and understanding with you.