Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages 33%

By The Hacker News36%

7/10/2026, 6:09:15 PM

BS Summary: This article contains 22 faulty reasoning types, including Appeal to Authority, Unattributed Quote, and Quote-first Misdirection, with Negativity Bias as the most egregious example at 43.9% saturation with 389 hits. Analysis detected 2,001 faulty-reasoning hits from 887 analyzed words, generating a BS Score of 41.3% and a BS Rank of 33% (14,825 of 21,887 articles). This article is better (less manipulative) than 67.70% of the article peer group.

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages 
 Ravie Lakshmanan  Jul 10, 2026 Software Supply Chain / Malware 
Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases. 
The compromised version, @injectivelabs/sdk-ts@1.20.21 , came embedded with fake telemetry functionality that exfiltrated data from cryptocurrency wallets. 
The version was released on July 8, 2026, but has since been deprecated on the registry. 
That said, the release artifacts belonging to the compromised version are still available for download from GitHub as of writing. 
"The malicious functionality was introduced to the project's official GitHub repository through commits submitted by a GitHub account belonging to a developer with an established history of contributions to the repository," Socket said . 
The software supply chain security firm said the threat actor behind the attack also published version 1.20.21 across 17 additional @injectivelabs scoped packages that depended on and pinned the malicious SDK version, thereby putting transitive users who may not have installed the library directly. 
This includes - 
@injectivelabs/utils 
@injectivelabs/networks 
@injectivelabs/ts-types 
@injectivelabs/exceptions 
@injectivelabs/wallet-base 
@injectivelabs/wallet-core 
@injectivelabs/wallet-cosmos 
@injectivelabs/wallet-private-key 
@injectivelabs/wallet-evm 
@injectivelabs/wallet-trezor 
@injectivelabs/wallet-cosmostation 
@injectivelabs/wallet-ledger 
@injectivelabs/wallet-wallet-connect 
@injectivelabs/wallet-magic 
@injectivelabs/wallet-strategy 
@injectivelabs/wallet-turnkey 
@injectivelabs/wallet-cosmos-strategy 
The malware present within the package is fairly simple and straightforward, which gets triggered when the library functionality is used by an unsuspecting developer. 
By avoiding lifecycle scripts and not launching it during the installation phase, it helps the malware fly under the radar. 
Specifically, the poisoned version has been found to modify legitimate functions used in workflows to generate private keys by invoking a "trackKeyDerivation()" function under the guise of collecting anonymized usage metrics for SDK optimization. 
"Tracks which key derivation methods are used (hex vs mnemonic) and derives timing patterns to help the SDK team identify performance bottlenecks and understand adoption of different key formats across the ecosystem," reads the description of the supposed telemetry function. 
"All metrics are fire-and-forget and never block or affect key derivation." 
According to Socket, parameters passed to the function include a hard-coded marker describing the method used to generate the private key and the actual sensitive information needed for generating the private key. 
The captured material is enough for the threat actor to regenerate the private key at their end. 
"The malware adds crypto wallet stealing logic to a crypto wallet package, every time a legitimate user creates or uses the logic that reads mnemonic phrases  which are basically the master key for any crypto wallet, the malware reads them and sends them to the remote server," OX Security said . 
In an attempt to reduce the number of outbound requests, the exfiltration mechanism is designed to append multiple key derivations over a two-second window into a single queue and then send them in the form of an HTTPS POST request to an external server ("testnet.archival.chain.grpc-web.injective[.]network") in a single beacon. 
StepSecurity noted the malicious release was facilitated through the repository's own trusted-publisher (OIDC) pipeline, adding that the malicious commits were authored and pushed under the identity of an existing, trusted maintainer ("thomasRalee"). 
Users who have installed the malicious version are recommended to update to the newly published, clean version of the package (1.20.23), treat any private key or mnemonic phrase passed through the package as compromised and rotate them, and check for transitive dependencies. 
Found this article interesting? 
Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post. 
Credential Theft , cryptocurrency , data theft , Developer Security , GitHub , Malware , NPM , Open Source Security , Package Security , Software Supply Chain 
ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories 
Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability 
New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets 
Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs 
New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries 
OpenAI Previews GPT-5.6 Sol With Restricted Access and Stronger Cyber Safeguards 
FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys 
Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw 
Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts 
 Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More 
Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks 
WhatsApp is Finally Getting Usernames to Help Keep Phone Numbers Private 
Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild 
New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials 
AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks 
282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study 
GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks 
Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data 
RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS 
 Featured Resources 
What 200+ Security Teams Reveal About Using IP Intelligence in 2026 
Get Hands-On SANS Training for Today’s Cyber Defense and Offensive Security Challenges 
See What’s Really Exposed Across Your IT, OT, IoT, Cloud, and Mobile Assets 
Get Gartner’s Guide to AI Agent Supervision and Runtime Controls 
Article reasoning-pattern comparisonThis article: 0.0%The Hacker News: 1.8%The Hacker News: 1.9%Confirmation Bias0.0%This article: 1.8%The Hacker News: 0.8%The Hacker News: 1.2%Anchoring Bias1.8%This article: 7.8%The Hacker News: 3.5%The Hacker News: 3.3%Availability Heuristic7.8%This article: 8.2%The Hacker News: 1.5%The Hacker News: 1.5%Representativeness Heuristic8.2%This article: 0.0%The Hacker News: 0.3%The Hacker News: 0.6%Hindsight Bias0.0%This article: 1.9%The Hacker News: 2.7%The Hacker News: 2.5%Overconfidence Bias1.9%This article: 6.2%The Hacker News: 2.8%The Hacker News: 2.7%Framing Effect6.2%This article: 6.2%The Hacker News: 1.3%The Hacker News: 1.0%Loss Aversion6.2%This article: 1.2%The Hacker News: 0.6%The Hacker News: 0.6%Status Quo Bias1.2%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%Sunk Cost Effect0.0%This article: 2.5%The Hacker News: 1.4%The Hacker News: 1.3%Optimism Bias2.5%This article: 4.5%The Hacker News: 1.4%The Hacker News: 1.6%Pessimism Bias4.5%This article: 43.9%The Hacker News: 6.6%The Hacker News: 6.7%Negativity Bias43.9%This article: 0.0%The Hacker News: 1.5%The Hacker News: 0.8%Self-Serving Bias0.0%This article: 3.7%The Hacker News: 0.3%The Hacker News: 0.4%Fundamental Attribution Error3.7%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.1%Actor-Observer Bias0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%In-Group Bias0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.3%Out-Group Homogeneity Bias0.0%This article: 0.0%The Hacker News: 0.8%The Hacker News: 0.6%Halo Effect0.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Horn Effect0.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Dunning-Kruger Effect0.0%This article: 6.2%The Hacker News: 1.0%The Hacker News: 1.5%Recency Bias6.2%This article: 0.0%The Hacker News: 0.3%The Hacker News: 0.3%Primacy Effect0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%Blind-Spot Bias0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%Ad Hominem0.0%This article: 0.0%The Hacker News: 0.2%The Hacker News: 0.1%Straw Man0.0%This article: 23.1%The Hacker News: 3.7%The Hacker News: 4.0%Appeal to Authority23.1%This article: 0.0%The Hacker News: 2.4%The Hacker News: 1.6%False Dilemma0.0%This article: 0.0%The Hacker News: 0.4%The Hacker News: 0.5%Slippery Slope0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%Circular Reasoning0.0%This article: 5.0%The Hacker News: 5.1%The Hacker News: 4.3%Hasty Generalization5.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.1%Red Herring0.0%This article: 11.5%The Hacker News: 0.3%The Hacker News: 0.2%Bandwagon11.5%This article: 0.0%The Hacker News: 1.3%The Hacker News: 1.1%Appeal to Emotion0.0%This article: 0.0%The Hacker News: 0.9%The Hacker News: 0.5%Begging the Question0.0%This article: 9.7%The Hacker News: 1.8%The Hacker News: 1.9%Post Hoc (False Cause)9.7%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Tu Quoque0.0%This article: 0.0%The Hacker News: 0.4%The Hacker News: 0.6%Burden of Proof0.0%This article: 0.0%The Hacker News: 0.2%The Hacker News: 0.1%Appeal to Nature0.0%This article: 0.0%The Hacker News: 0.5%The Hacker News: 0.3%Composition/Division0.0%This article: 0.0%The Hacker News: 1.2%The Hacker News: 1.0%Anecdotal0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%No True Scotsman0.0%This article: 9.5%The Hacker News: 1.3%The Hacker News: 2.3%Ambiguity (Equivocation)9.5%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Gambler’s Fallacy0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.0%Middle Ground0.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Personal Incredulity0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%Special Pleading0.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.1%Genetic Fallacy0.0%This article: 21.4%The Hacker News: 0.8%The Hacker News: 1.4%Unattributed Quote21.4%This article: 19.2%The Hacker News: 0.3%The Hacker News: 0.9%Quote-first Misdirection19.2%This article: 17.1%The Hacker News: 1.9%The Hacker News: 2.3%Biased Writer Voice17.1%This article: 6.2%The Hacker News: 5.0%The Hacker News: 4.4%Indoctrination6.2%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Politically Right Leaning Bias0.0%This article: 8.8%The Hacker News: 6.7%The Hacker News: 3.0%Attempt to Sell a Product or S…8.8%

887 words analyzed.

Speakers

4speakers18%attributed speech725writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 8 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageRavie Lakshmanan • 12 words • 0.0% coverageWriter's voice • 33 words • 100.0% coverageWriter's voice • 17 words • 100.0% coverageWriter's voice • 16 words • 0.0% coverageWriter's voice • 20 words • 0.0% coverageSocket • 34 words • 100.0% coverageWriter's voice • 44 words • 100.0% coverageWriter's voice • 3 words • 0.0% coverageWriter's voice • 1 words • 0.0% coverageWriter's voice • 1 words • 0.0% coverageWriter's voice • 1 words • 0.0% coverageWriter's voice • 1 words • 0.0% coverageWriter's voice • 1 words • 0.0% coverageWriter's voice • 1 words • 0.0% coverageWriter's voice • 1 words • 0.0% coverageWriter's voice • 1 words • 0.0% coverageWriter's voice • 1 words • 0.0% coverageWriter's voice • 1 words • 0.0% coverageWriter's voice • 1 words • 0.0% coverageWriter's voice • 1 words • 0.0% coverageWriter's voice • 1 words • 0.0% coverageWriter's voice • 1 words • 0.0% coverageWriter's voice • 1 words • 0.0% coverageWriter's voice • 1 words • 0.0% coverageWriter's voice • 1 words • 0.0% coverageWriter's voice • 24 words • 100.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 34 words • 100.0% coverageWriter's voice • 40 words • 100.0% coverageWriter's voice • 11 words • 100.0% coverageSocket • 32 words • 100.0% coverageWriter's voice • 17 words • 0.0% coverageOX Security • 52 words • 100.0% coverageWriter's voice • 49 words • 0.0% coverageStepSecurity • 32 words • 100.0% coverageWriter's voice • 42 words • 100.0% coverageWriter's voice • 4 words • 100.0% coverageWriter's voice • 16 words • 100.0% coverageWriter's voice • 27 words • 0.0% coverageWriter's voice • 12 words • 100.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 16 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 3 words • 0.0% coverageWriter's voice • 11 words • 100.0% coverageWriter's voice • 12 words • 100.0% coverageWriter's voice • 13 words • 100.0% coverageWriter's voice • 10 words • 100.0% coverage
Selected voice

OX Security

100%flagged-word coverage
52 attributed words32% of attributed speech93% writer coverage
0%50.0%100.0%Unattributed Quote+94.5 ptsWriter: 5.5%OX Security: 100.0%100.0%Quote-first Misdirection+88.4 ptsWriter: 11.6%OX Security: 100.0%100.0%Biased Writer Voice-21.0 ptsWriter: 21.0%OX Security: 0.0%0.0%Attempt to Sell a Product -10.8 ptsWriter: 10.8%OX Security: 0.0%0.0%Indoctrination-7.6 ptsWriter: 7.6%OX Security: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.