Incident case file
Sign in to watchInjective Labs SDK npm Supply Chain Backdoor
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: Commits pushed under the identity of a trusted maintainer account, 'thomasRalee' (thomas.leera@gmail.com), whose credentials were compromised. No separate on-chain attacker wallet identified — this was a code-supply-chain compromise, not a direct fund theft.
Timeline: June 8, 2026: suspicious commits first appear on a branch named 'test-backdoor-check' in the Injective SDK repository. July 8, 2026, 20:24 UTC: first malicious commit lands on a release branch. 20:59:17-21:00:39 UTC: 18 compromised packages are published to npm as version 1.20.21, containing code designed to exfiltrate private keys and seed phrases during normal key-derivation flows. 21:16:32 UTC: a revert commit is pushed, still under the compromised 'thomasRalee' identity. 21:47:52-21:49:16 UTC: a clean version, 1.20.23, is published, superseding the compromised release. Security researchers at Socket, StepSecurity, and Ox Security detect and report the incident within hours of publication. Injective CEO Eric Chen publicly confirms that 'no funds on the Injective network were at risk.' No confirmed victim funds were lost.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)