{
  "Event": {
    "analysis": "1",
    "date": "2026-07-09",
    "extends_uuid": "",
    "info": "[Threat Intel] Compromised Injective SDK npm Package Exfiltrates Wallet Keys and Mnemonics",
    "protected": false,
    "publish_timestamp": "1784349346",
    "published": true,
    "threat_level_id": "2",
    "timestamp": "1784349345",
    "uuid": "eca6afa5-b106-45e7-bd05-802ce4a7ced0",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#bb2745",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Standard Encoding - T1132.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#d3f567",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"JavaScript - T1059.007\"",
        "relationship_type": ""
      },
      {
        "colour": "#ed66f6",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"",
        "relationship_type": ""
      },
      {
        "colour": "#256f6a",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"DLL - T1574.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#f95f85",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Credentials In Files - T1552.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#08221e",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Steal Application Access Token - T1528\"",
        "relationship_type": ""
      },
      {
        "colour": "#a9f8b1",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Compromise Host Software Binary - T1554\"",
        "relationship_type": ""
      },
      {
        "colour": "#d596aa",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Compromise Software Supply Chain - T1195.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exfiltration to Cloud Storage - T1567.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#a42e64",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Data from Information Repositories - T1213\"",
        "relationship_type": ""
      },
      {
        "colour": "#92e858",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Local Accounts - T1078.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:producer=\"37ebf9d7-5e9a-466f-a42c-6e60313db868\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#130049",
        "local": false,
        "name": "rectifyq:sub-category=\"campaign-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#18005e",
        "local": false,
        "name": "rectifyq:topic=\"supply-chain\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:software-vendor=\"npm\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783681215",
        "to_ids": false,
        "type": "link",
        "uuid": "9b205139-5421-4e0d-b175-dfa677e36562",
        "value": "https://socket.dev/blog/compromised-injective-sdk-npm-package"
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783681215",
        "to_ids": false,
        "type": "text",
        "uuid": "241827b4-ad0d-4fdd-b102-959563861c03",
        "value": "A compromised version of the Injective Labs TypeScript SDK npm package was published containing malicious code that exfiltrates cryptocurrency wallet private keys and mnemonic phrases. The malicious version 1.20.21 was published on June 8, 2026, through a compromised developer account with established repository access. The malware hooks key generation functions to capture sensitive wallet data and exfiltrates it via base64-encoded POST requests to legitimate Injective infrastructure endpoints, disguising the traffic. The threat actor amplified impact by publishing 17 additional scoped packages pinned to the malicious version. Though quickly detected and contained within hours, the compromised package received approximately 310 downloads. The package has roughly 50,000 weekly downloads and 87 dependent packages, presenting significant supply chain risk to cryptocurrency wallet implementations."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1783681215",
        "to_ids": false,
        "type": "text",
        "uuid": "5c4fc5de-f5d2-4596-9685-f76e3486acff",
        "value": "Name: Compromised Injective SDK npm Package Exfiltrates Wallet Keys and Mnemonics\nAuthor: AlienVault\nAdversary: \nTags: [\"npm compromise\", \"wallet credential exfiltration\", \"typescript sdk\", \"blockchain\", \"developer account compromise\", \"cryptocurrency theft\", \"supply chain attack\", \"infostealer\"]\nTgtd countries: []\nMlwr families: []\nAttack_ids: [\"T1132.001\", \"T1059.007\", \"T1539\", \"T1574.001\", \"T1552.001\", \"T1528\", \"T1041\", \"T1554\", \"T1195.002\", \"T1567.002\", \"T1213\", \"T1071.001\", \"T1078.003\"]\nIndustries: [\"Technology\"]"
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784349175",
        "to_ids": true,
        "type": "url",
        "uuid": "cc8c6bcb-4399-477e-9acb-4bc5299b4b38",
        "value": "https://testnet.archival.chain.grpc-web.injective.network",
        "Tag": [
          {
            "colour": "#f08989",
            "local": false,
            "name": "NotFoundError",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check: 18/07/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784344625",
        "to_ids": true,
        "type": "sha256",
        "uuid": "fdee5632-66e6-4412-b2f4-3dd658c08979",
        "value": "103c4e6181151c1bcfedc41506cd1815458c38375d08a8fcd9981dbe0b965ce0",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check: 18/07/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784344625",
        "to_ids": true,
        "type": "sha256",
        "uuid": "d86a646a-db69-41b7-ae48-bc8d15ba429f",
        "value": "9a59eb454f3ca3fe91214136ee5edd417cc47a80e6f169b52099d6561944baf9",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1784349196",
        "to_ids": true,
        "type": "hostname",
        "uuid": "7e297d04-f1ae-4d2d-9508-c07b642f557b",
        "value": "testnet.archival.chain.grpc-web.injective.network",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      }
    ]
  }
}