惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Project Zero
Project Zero
月光博客
月光博客
Y
Y Combinator Blog
T
The Blog of Author Tim Ferriss
O
OpenAI News
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Know Your Adversary
Know Your Adversary
Last Week in AI
Last Week in AI
S
Securelist
Engineering at Meta
Engineering at Meta
博客园 - 司徒正美
P
Privacy & Cybersecurity Law Blog
T
Tailwind CSS Blog
F
Fortinet All Blogs
博客园 - 三生石上(FineUI控件)
Scott Helme
Scott Helme
MyScale Blog
MyScale Blog
P
Proofpoint News Feed
云风的 BLOG
云风的 BLOG
C
Cisco Blogs
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
小众软件
小众软件
U
Unit 42
Microsoft Azure Blog
Microsoft Azure Blog
Hacker News: Ask HN
Hacker News: Ask HN
Hugging Face - Blog
Hugging Face - Blog
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
SecWiki News
SecWiki News
宝玉的分享
宝玉的分享
P
Proofpoint News Feed
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
H
Hackread – Cybersecurity News, Data Breaches, AI and More
L
Lohrmann on Cybersecurity
IT之家
IT之家
Security Archives - TechRepublic
Security Archives - TechRepublic
I
InfoQ
S
Security @ Cisco Blogs
Webroot Blog
Webroot Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
F
Full Disclosure
D
Darknet – Hacking Tools, Hacker News & Cyber Security
The GitHub Blog
The GitHub Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
Jina AI
Jina AI
Cyberwarzone
Cyberwarzone
人人都是产品经理
人人都是产品经理
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
B
Blog RSS Feed
Apple Machine Learning Research
Apple Machine Learning Research

Socket

Fake Corepack Site Distributes Infostealer and Proxyware to ... Large-Scale GitHub Actions Abuse Powers a Distributed cPanel... New Study Identifies 53 Slopsquatting Targets Across 5 Front... White House Launches Gold Eagle Initiative to Manage Surge i... Suno Breached via Shai-Hulud Worm, Leaked Code Exposes AI Mu... Next.js moves to scheduled security releases - Socket 11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windo... Compromised npm Packages in the AsyncAPI Namespace Deliver M... jscrambler npm Package Compromised in Supply Chain Attack - ... Fake Braintree NuGet Package Skims Credit Cards and Harvests... npm v12 Ships With Install Scripts Off by Default, Begins De... Malicious Go Module Exposes GitHub Malware Lure Network Span... pnpm 11.10 Hardens Registry Authentication to Block Token Re... Coordinated npm and PyPI Campaign Typosquats Popular Secure ... Node.js Considers Public Workflow for Security Reports Amid ... PolinRider: North Korea-Linked Supply Chain Campaign Expands... Risky Biz Podcast: AI Agents Are Raising the Stakes for Soft... Chrome and Firefox Extensions Posing as Free VPNs Add Clipbo... Miasma Mini Shai-Hulud Hits ImmobiliareLabs npm Packages - S... Rolldown Pulls Rust React Compiler Integration After Binary ... Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and Git... Frontier AI Is Now Critical Infrastructure - Socket The Code You Didn't Write Is Still Yours to Defend - Socket GitHub Actions Checkout Now Blocks Risky pull_request_target... Introducing Repository Access Permissions and Custom Roles -... Socket MCP Adds Org Alerts, Threat Feed Review, and Package ... Socket Firewall Now Blocks Malicious VS Code and Open VSX Ex... 140+ Mastra npm Packages Compromised in Coordinated Supply C... npm Package Uses Prompt Injection and Token Flooding to Disr... Introducing Manifest Alerts - Socket GlassWASM: WebAssembly Malware Found in Trojanized Open VSX ... Socket for Linear Is Now Available - Socket US Government Forces Anthropic to Pull Claude Fable Days After Launch 152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Faked Google Search Traffic Andrew Becherer Joins Socket as Chief Information Security Officer Socket Partners with Replit to Block Malicious Packages in AI-Powered Development npm Tooling Bug Incorrectly Marks One-Character Packages as Security Holders Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI Wheels Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave RubyGems Adds Cooldown Feature to Bundler for Newly Published Gems RubyGems Adds Cooldown Feature to Bundler for Newly Published Gems pnpm 11.5 Adds Support for Recognizing npm Staged Publishes pnpm 11.5 Adds Support for Recognizing npm Staged Publishes Federal Audit Finds NIST Wasted Funds With No Plan to Clear NVD Backlog Federal Audit Finds NIST Wasted Funds With No Plan to Clear NVD Backlog Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages Famous Chollima Targets PHP Developers Through Compromised Packagist Package Famous Chollima Targets PHP Developers Through Compromised Packagist Package Rust Moves to Restrict LLM Use in Contributions After Months of Internal Debate Rust Moves to Restrict LLM Use in Contributions After Months of Internal Debate Malicious NuGet Package Impersonates Sicoob SDK to Exfiltrate Banking Certificates and Passwords Malicious NuGet Package Impersonates Sicoob SDK to Exfiltrate Banking Certificates and Passwords Feross on TBPN: Socket's Series C and the State of Software Supply Chain Security Feross on TBPN: Socket's Series C and the State of Software Supply Chain Security OSV Withdraws 157 Malware Reports After Automated False Positives Hit npm and PyPI OSV Withdraws 157 Malware Reports After Automated False Positives Hit npm and PyPI TrapDoor Crypto Stealer Supply Chain Attack Hits 34 Packages and Hundreds of Versions Across npm, PyPI, and Crates.io TrapDoor Crypto Stealer Supply Chain Attack Hits 34 Packages and Hundreds of Versions Across npm, PyPI, and Crates.io Laravel Lang Compromised with RCE Backdoor Across 700+ Versions Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist and Node.js Projects AI Has Taken Over Open Source npm Invalidates Granular Access Tokens as Mini Shai-Hulud Sweeps the Registry Coruna Respawned: Compromised art-template npm Package Leads to iOS Browser Exploit Kit Socket raises $60M Series C at $1B valuation led by Thrive Capital to secure AI-driven software development Socket Raises $60M Series C at a $1B Valuation to Help Enterprises Build Securely With AI Popular Go Decimal Library Targeted by Long-Running Typosquat with DNS Backdoor Active Supply Chain Attack Compromises @antv Packages on npm Popular node-ipc npm Package Infected with Credential Stealer TeamPCP and BreachForums Launch $1,000 Contest for Supply Chain Attacks Packagist Urges Immediate Composer Update After GitHub Actions Token Leak GemStuffer Campaign Abuses RubyGems as Exfiltration Channel Targeting UK Local Government Socket Named to Rising in Cyber 2026 List of Top Cybersecurity Startups TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud Supply-Chain Attack fsnotify Maintainer Dispute Sparks Supply Chain Concerns Socket Releases Free Certified Patches for Critical vm2 Sandbox Escape 5 Malicious NuGet Packages Impersonate Chinese UI Libraries to Distribute Crypto Wallet and Credential Stealer pnpm 11 Adds Supply Chain Protection Defaults for Minimum Release Age and Exotic Subdependencies PyPI Fixes High-Severity Access Control Issues Found in Security Audit Malicious Ruby Gems and Go Modules Impersonate Developer Tools to Steal Secrets and Poison CI Mini Shai-Hulud Spreads to Packagist: Malicious Intercom PHP Package Follows npm Compromise Intercom’s npm Package Compromised in Ongoing Mini Shai-Hulud Worm Attack lightning PyPI Package Compromised in Supply Chain Attack Malicious npm Package Brand-Squats TanStack to Exfiltrate Environment Variables SAP CAP npm Packages Hit by Supply Chain Attack Socket Has Acquired Secure Annex 73 Open VSX Sleeper Extensions Linked to GlassWorm Show New Malware Activations Introducing Reachability for PHP Introducing Data Exports Malicious Checkmarx Artifacts Found in Official KICS Docker Repository and Code Extensions Introducing Organization Notifications in Socket Introducing Reports: An Extensible Reporting Framework for Socket Data Socket for Jira Is Now Available Socket Named Top Sales Organization by RepVue NIST Officially Stops Enriching Most CVEs as Vulnerability Volume Skyrockets Socket Selected for OpenAI's Cybersecurity Grant Program Feross on the 10 Minutes or Less Podcast: Nobody Reads the Code 108 Chrome Extensions Linked to Data Exfiltration and Session Theft via Shared C2 Infrastructure Node.js Drops Bug Bounty Rewards After Funding Dries Up The Hidden Blast Radius of the Axios Compromise
Compromised Injective SDK npm Package Exfiltrates Wallet Key...
Karlo Zanki · 2026-07-09 · via Socket

Sidebar CTA Background

Secure your dependencies with us

Socket proactively blocks malicious open source packages in your code.

Install

@injectivelabs/sdk-ts@1.20.21 records private keys and mnemonics, enabling wallet compromise via 17 scoped packages pinned to the malicious version.

Socket detected a malicious @injectivelabs/sdk-ts@1.20.21 release published to npm with fake telemetry functionality that exfiltrates wallet private keys and mnemonic phrases. The affected package is part of the Injective Labs TypeScript SDK and receives roughly 50,000 weekly downloads, making the incident significant for developers and applications that handle Injective wallet workflows.

The malicious functionality was introduced to the project’s official GitHub repository through commits submitted by a GitHub account belonging to a developer with an established history of contributions to the repository. The suspicious activity started on June 8, 2026 20:06 GMT+2 with commits likely used to test the access and rights by creating a branch called test-backdoor-check. The malicious version 1.20.21 was published at 22:59 GMT+2 but the malicious activity appears to be detected and contained relatively fast by the true owner of the developer account. A commit reverting the fix has been submitted to the GitHub repository at 23:18 GMT+2 and a clean version was published at 23:48 GMT+2. However, release artifacts belonging to the compromised version were still present in release pages of the corresponding GitHub repository at the moment of writing. Compromised version of the package was deprecated in npm but still not removed at the moment of writing.

The impact extends beyond direct users of @injectivelabs/sdk-ts. The threat actor also published version 1.20.21 across 17 additional @injectivelabs scoped packages that depended on and pinned the malicious SDK version, exposing transitive users who may not have installed @injectivelabs/sdk-ts directly.

Socket package view for npm/@injectivelabs/sdk-ts, showing a known-malware alert.

Compromised Packages and Versions#

Only one version of the @injectivelabs/sdk-ts package contains the malicious functionality, but other packages from the @injectivelabs scope have a version 1.20.21 released and each of them has a dependency to the @injectivelabs/sdk-ts package pinned to the malicious version 1.20.21

Malicious versions of the packages from the scope that directly or transitively depend on the malicious version of the compromised package:

The Stealer Functionality#

The malicious functionality is minimalistic and straightforward. The execution is not triggered at install time, but rather during usage of the library functionality. Such approach usually helps keep the malicious functionality under the radar. The malicious code is located in /dist/esm/accounts-jQ1GSgaW.js and /dist/cjs/accounts-Cy0p4lLW.cjs files. The functions fromMnemonic and fromHex used in regular workflows to generate private keys are hooked with a call to the trackKeyDerivation function.

var PrivateKey = class PrivateKey {
	constructor(wallet) {
		require_defineProperty._defineProperty(this, "wallet", void 0);
		this.wallet = wallet;
	}
	/**
	* Generate new private key with random mnemonic phrase
	* @returns { privateKey: PrivateKey, mnemonic: string }
	*/
	static generate() {
		const mnemonic = (0, __scure_bip39.generateMnemonic)(__scure_bip39_wordlists_english.wordlist);
		return {
			privateKey: PrivateKey.fromMnemonic(mnemonic),
			mnemonic
		};
	}
	/**
	* Create a PrivateKey instance from a given mnemonic phrase and a HD derivation path.
	* If path is not given, default to Band's HD prefix 494 and all other indexes being zeroes.
	* @param {string} words the mnemonic phrase
	* @param {string|undefined} path the HD path that follows the BIP32 standard (optional)
	* @returns {PrivateKey} Initialized PrivateKey object
	*/
	static fromMnemonic(words, path = require_constants.DEFAULT_DERIVATION_PATH) {
		trackKeyDerivation("fm", words);
		return new PrivateKey(new ethers.Wallet(ethers.HDNodeWallet.fromPhrase(words, void 0, path).privateKey));
	}
A hooked call to the malicious trackKeyDerivation function responsible for data logging and exfiltration. Arguments passed to the function include a hardcoded marker describing the method used to generate the private key and the actual sensitive information needed for generating the private key. With these information threat actors can regenerate the private key in their environment.

This function records key derivation events by logging method used to create derivation and the sensitive information used to derive the key. In the case of the fromMnemonic function, the full mnemonic phrase is recorded, and in the case of the fromHex function, the private-key material or a representation of it is recorded. Finally these records are base64-encoded and silently exfiltrated through a POST request to a char-obfuscated public infrastructure endpoint https://testnet[.]archival[.]chain[.]grpc-web[.]injective[.]network. By using public infrastructure endpoints belonging to InjectiveLabs, the threat actor blends the network traffic generated during exfiltration with the network traffic generated during typical usage of InjectiveLabs’ software products. The exfiltrated material is sufficient for threat actor to recreate private keys and get access to wallets containing victims crypto assets.

Impact#

The compromised @injectivelabs/sdk-ts is a popular package with approximately 50,000 weekly downloads. It has 87 dependent packages according to npm data and the number of transitive dependencies is likely even larger. The threat actor tried to amplify the impact by simultaneously publishing version 1.20.21 across several other npm packages under the @injectivelabs scope. These packages included a direct or transitive dependencies to the compromised package which were pinned to the malicious versions 1.20.21.

While the compromise was quickly detected by the developer whose account was used to create the malicious commits, the campaign itself isn’t yet fully contained. The malicious version of the compromised package hasn’t yet been removed from the npm repository, but only deprecated with a warning message from the author that it is a compromised version and it shouldn’t be used. However, this means that the version is still present and downloadable. Same goes for the release artifacts in the GitHub repository.

Version information from npm repository proving that the malicious version has been deprecated but not yet removed. According to the official stats, the malicious version has been downloaded 310 times. The true impact can be considered relatively insignificant, given the potential impact based on the popularity of the project. The bigger damage was averted thanks to the quick reaction from the developer behind the compromised GitHub account.

Defensive Guidance#

Recommended actions for developers:

  1. Audit your package.json for packages from @injectivelabs scope not pinned to a specific version that could be resolved to version 1.20.21. Change them to the newly published, clean version 1.20.23.
  2. Any private key or mnemonic phrase passed through these packages should be treated as compromised. Move funds and rotate keys and mnemonics.
  3. Check for transitive dependencies. Threat actors purposely published versions of packages that depend on @injectivelabs/sdk-ts package and had them pinned to the malicious version 1.20.21, so auditing direct dependencies is not sufficient.

Indicators of Compromise#

Compromised npm packages

SHA-256 Hashes

  • 103c4e6181151c1bcfedc41506cd1815458c38375d08a8fcd9981dbe0b965ce0 - /dist/cjs/accounts-Cy0p4lLW.cjs file containing the infostealer functionality
  • 9a59eb454f3ca3fe91214136ee5edd417cc47a80e6f169b52099d6561944baf9 /dist/esm/accounts-jQ1GSgaW.js file containing the infostealer functionality