datadog-security-labs · Crawled Jul 18, 2026

Not-so-anonymous telemetry: The @injectivelabs/sdk-ts backdoor

1 IoCs
Read original article ↗

AI Summary

On July 8, 2026, a malicious version (1.20.21) of the npm package @injectivelabs/sdk-ts was published, containing a backdoored module that exfiltrated cryptocurrency wallet mnemonic phrases and private keys. The compromise occurred via a suspicious GitHub commit pushed directly to the main branch, originating from an unfamiliar timezone for the maintainer. Sensitive data was captured during wallet loading and sent via the X-Request-Id HTTP header to a malicious domain designed to mimic a legitimate Injective testnet service. The package was compromised for approximately 49 minutes before being reverted and replaced with a clean version.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
Domain testnet[.]archival[.]chain[.]grpc-web[.]injective[.]network Details →