FixVibe

high

Compromised @injectivelabs/sdk-ts exfiltrates wallet keys through fake telemetry

FixVibe GitHub repo scans now flag @injectivelabs/sdk-ts 1.20.21 and associated @injectivelabs 1.20.21 package evidence in manifests and lockfiles as a version-based malware advisory.

CWE-506

What happened

Security researchers reported that @injectivelabs/sdk-ts release 1.20.21 was compromised and later replaced by clean 1.20.23 releases. npm now marks the compromised SDK version as a security issue. Related @injectivelabs packages were also published at 1.20.21 and could pull the compromised SDK transitively. [S1][S2][S3][S4]

Impact

Applications, CI jobs, developer tooling, or wallet workflows that installed the affected package version and then generated, imported, or signed with Injective wallet material should treat impacted wallet secrets as potentially exposed. Repository dependency evidence alone does not prove runtime execution, wallet derivation, exfiltration, or fund loss. [S1][S2][S3]

How FixVibe covers it

FixVibe's GitHub repo scans flag package manifests and npm, pnpm and Yarn lockfiles that include @injectivelabs/sdk-ts 1.20.21 or associated @injectivelabs 1.20.21 packages, with the file, dependency path and remediation guidance.

Fixes

  • Upgrade every @injectivelabs dependency to 1.20.23 or a newer clean release.
  • Regenerate npm, pnpm, or Yarn lockfiles from a trusted registry state, then rebuild dependency caches, Docker layers, serverless bundles, mobile artifacts, and CI images that may have installed 1.20.21.
  • Check transitive dependencies because associated @injectivelabs 1.20.21 packages can pull the compromised SDK even when sdk-ts is not listed directly.
  • If the affected package may have run in an environment that generated, imported, or signed Injective wallets, move funds and rotate mnemonics or private keys according to wallet incident-response policy.