What happened
Security researchers reported that @injectivelabs/sdk-ts release 1.20.21 was compromised and later replaced by clean 1.20.23 releases. npm now marks the compromised SDK version as a security issue. Related @injectivelabs packages were also published at 1.20.21 and could pull the compromised SDK transitively. [S1][S2][S3][S4]
Impact
Applications, CI jobs, developer tooling, or wallet workflows that installed the affected package version and then generated, imported, or signed with Injective wallet material should treat impacted wallet secrets as potentially exposed. Repository dependency evidence alone does not prove runtime execution, wallet derivation, exfiltration, or fund loss. [S1][S2][S3]
How FixVibe covers it
FixVibe's GitHub repo scans flag package manifests and npm, pnpm and Yarn lockfiles that include @injectivelabs/sdk-ts 1.20.21 or associated @injectivelabs 1.20.21 packages, with the file, dependency path and remediation guidance.
Fixes
- Upgrade every
@injectivelabsdependency to1.20.23or a newer clean release. - Regenerate npm, pnpm, or Yarn lockfiles from a trusted registry state, then rebuild dependency caches, Docker layers, serverless bundles, mobile artifacts, and CI images that may have installed
1.20.21. - Check transitive dependencies because associated
@injectivelabs1.20.21packages can pull the compromised SDK even whensdk-tsis not listed directly. - If the affected package may have run in an environment that generated, imported, or signed Injective wallets, move funds and rotate mnemonics or private keys according to wallet incident-response policy.
