Injective Labs GitHub Repo Compromised — 18 npm Packages Backdoored to Exfiltrate DeFi Wallet Private Keys and Mnemonics
On July 8, attackers used a hijacked trusted maintainer account ('thomasRalee') to push malicious commits into Injective Labs' official GitHub repository, triggering the project's own OIDC trusted-publisher pipeline to auto-publish version 1.20.21 of @injectivelabs/sdk-ts and 17 dependent packages — all hooked to silently capture BIP-39 mnemonic seed phrases and private keys at wallet creation and exfiltrate them disguised as gRPC-Web telemetry to Injective's own public infrastructure endpoints. The window was under one hour before reversion, but the SDK sees 50,000 weekly downloads across a DeFi ecosystem where developers routinely handle production wallet credentials. Any developer or application that instantiated a wallet during the exposure window should treat all key material as compromised and migrate funds immediately.
The window was under one hour before reversion, but the SDK sees 50,000 weekly downloads across a DeFi ecosystem where developers routinely handle production wallet credentials.
This intelligence brief has been compiled from open-source reporting and corroborated across multiple threat intelligence sources. Defenders should treat the high severity rating as a guide to prioritization within their environment.
For the latest indicators of compromise, formatted SIEM queries, and unredacted actor intelligence related to this brief, DMZ Operator subscribers receive automated IOC packages via email the moment new advisories are published.