🚨 Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages Breach — Data Exposed
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages suffered a data breach. Here's what happened, what data was exposed, and what you should do right now.
What Happened
Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases.
The compromised version, @injectivelabs/sdk-ts@1.20.21, came embedded with fake telemetry functionality that exfiltrated data from cryptocurrency wallets. The version was
Impact
What You Should Do
If you have an account with Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages, take these steps immediately:
Is Your Website Secure?
Data breaches often exploit weak security configurations — missing Content-Security-Policy headers, misconfigured CORS, exposed API keys. These are exactly the issues ScanMyVibe detects in under 30 seconds.
[Scan your site free →](https://scanmyvibe.co/scan)
Timeline
This article is auto-generated by ScanMyVibe's breach monitoring system. Sources are verified but details may evolve as investigations progress. Last updated: 2026-07-11.
IS YOUR SITE NEXT?
Scan your website for the same vulnerabilities that cause breaches like this one.
SCAN FREE — 150+ CHECKS