Injective's SDK shipped a key-stealing update. The fix is rotating every key.
This is not a bad app bug. It is a poisoned developer package that can steal secrets before your code even runs.

CryptoVibe Desk · injective · security · supply-chain

- →Socket found malware in version 1.20.21 of @injectivelabs/sdk-ts, the official TypeScript SDK for Injective wallet workflows.
- →The attack lands through the npm package, so teams that installed it should treat touched keys as fully compromised.
- →Watch for Injective Labs to publish the diff, the fake endpoints, and a clean version before teams can scope the blast radius.
- SDK → An SDK is a set of code tools developers use to build apps for a specific platform.
- npm package → An npm package is a downloadable JavaScript or TypeScript library that apps can install as a dependency.
- seed phrase → A seed phrase is the backup phrase that can restore and control a crypto wallet.
Injective's TypeScript SDK shipped a poisoned 1.20.21 package.
Socket found malware in @injectivelabs/sdk-ts. It steals private wallet keys and seed phrases, according to crypto.news and CoinTelegraph. The malicious version was downloaded 300+ times. That number is a floor, not the blast radius.
The important part is where the attack lands. This is a supply-chain attack at install time, not a normal runtime bug. If your build server, wallet backend, or local dev machine pulled 1.20.21, the package itself becomes the hostile code.
The malware sent secrets through fake telemetry endpoints. The full Socket report, the endpoint names, and the package diff are not yet public. That limits what can be confirmed about the exact hook. It does not change the remediation.
Uninstalling 1.20.21 does not protect your bag. If your team handled Injective wallet flows with this package, treat every private key and seed phrase that touched that environment as copied. Rotation is the only number that matters.
At the contract level, stolen keys are not a reversible bug. They are authorization. Once an attacker has the signer, they can act like the owner until the owner moves funds or changes control.
This is the same boring npm failure crypto keeps relearning. A trusted dependency becomes the attacker. The engineers know this; the marketing team pretends the download count is the story. It isn't. The story is every key that package could see.
Injective Labs is calling this a package incident. It is full key compromise. Any team still scoping instead of rotating is already behind.
Within 72 hours, watch whether Injective Labs publishes a signed incident report naming the malicious diff, fake endpoints, and first clean replacement version.
Primary links and supporting reads used by the desk for this story.
Forward this.











