Injective SDK wallet-key exfiltration
Socket documented a compromised @injectivelabs/sdk-ts npm release that added fake telemetry behavior to sensitive key-derivation code and published related scoped packages pinned to the malicious version.
Also tracked as Injective SDK 1.20.21 compromise
- First observed
- Jun 8, 2026
- Last observed
- Jul 9, 2026
- Last reviewed
- Sep 2, 2026
- Tracking ended
- Sep 8, 2026
Record exports
Uncertainty and limitations
Read the evidence limits before acting on this record.
The reviewed report states that the malicious release was quickly contained, but downloadable artifacts and downstream exposure can vary. HOL does not infer victim losses from package download statistics.
- Any secret material processed by an affected library version must be handled according to the incident source guidance; Guard cannot retroactively revoke exposed keys.
Guard coverage and policy
What Guard's reviewed assertions do and do not claim for this campaign, and the reviewed starting points for defense.
Not covered, or partially covered
partial
Install-time review can help on eligible package actions, but the reported malicious behavior executed during library use; Guard does not claim universal mediation of arbitrary application code.
- Recipe available
Require review or explicit approval for new or changed dependency installation before an eligible package-manager action executes.
Coverage depends on the active Guard release, package manager, harness event surface, and local policy. It is not a guarantee that every dependency path is intercepted.
Safe next step. Campaign guidance is defensive context. It does not auto-apply policy or claim universal campaign coverage.
Timeline
Reviewed events, oldest first, each tied to a verified source.
- First observed
Injective SDK wallet-key exfiltration was first observed in the reviewed source material.
- Disclosure
The reviewed source published or updated its defensive analysis and remediation guidance.
Publication clock: 755.5 hours from reviewed disclosure timestamp to HOL publication; 12-hour critical target; historical backfill outside target.
Reviewed artifacts
The specific artifacts this record concerns, as reviewed. Names and versions are shown as text; a registry link is not recorded here.
@injectivelabs/sdk-ts@1.20.21npmpackage
Sources
Every claim on this record is traceable to the sources below.
Record HGTC-2026-INJECTIVE26