Injective Labs npm SDK Compromised via Hijacked Maintainer GitHub Account — 18 Packages Backdoored to Steal DeFi Wallet Keys
On July 8, attackers hijacked a trusted maintainer's GitHub account (thomasRalee) and used the repository's own OIDC trusted-publisher pipeline to publish @injectivelabs/sdk-ts@1.20.21 and 17 co-dependent packages — each containing key-derivation-telemetry.ts, which intercepts BIP-39 mnemonic seed phrases and private keys at wallet creation and exfiltrates them via HTTPS POST to an endpoint masquerading as Injective's own public gRPC-Web infrastructure. The malicious release, detected by Socket, Ox Security, and StepSecurity, was live for under an hour and downloaded approximately 310 times before the owner reverted the commits; the package has ~50,000 weekly downloads and 87 npm dependents, meaning transitive exposure is likely broader than direct downloads suggest. Any developer environment that called wallet key-generation functions during the compromise window should treat all mnemonic phrases and private keys as fully compromised and rotate immediately to version 1.20.23.
Any developer environment that called wallet key-generation functions during the compromise window should treat all mnemonic phrases and private keys as fully compromised and rotate immediately to version 1.20.23.
This intelligence brief has been compiled from open-source reporting and corroborated across multiple threat intelligence sources. Defenders should treat the high severity rating as a guide to prioritization within their environment.
For the latest indicators of compromise, formatted SIEM queries, and unredacted actor intelligence related to this brief, DMZ Operator subscribers receive automated IOC packages via email the moment new advisories are published.