What 45% Means: Securing the Code Your AI Agents Just Wrote

July 6, 2026
July 6, 2026

0 min read

AI Security
What 45% Means: Securing the Code Your AI Agents Just Wrote

@injectivelabs/sdk-ts version 1.20.21, published to npm on June 8, 2026 and disclosed by Socket's research team on July 9, 2026, is a malicious release of the official Injective Labs TypeScript SDK that exfiltrates wallet private keys and mnemonic phrases through a disguised telemetry function. The compromised version hooked the SDK's wallet-generation code, so any application that derived a wallet while running it had that wallet's secret material sent to an attacker-controlled endpoint. No CVE has been assigned to this incident as of publication; it is tracked as a malicious npm package release.

This post covers what happened, how the payload executed, every affected package and version, the indicators of compromise, and the first-hour response steps for any team with @injectivelabs/sdk-ts or another @injectivelabs-scoped package in its dependency tree

Attack Summary

  • Affected package: @injectivelabs/sdk-ts
  • Malicious version: 1.20.21
  • Clean version: 1.20.23
  • Ecosystem: npm
  • Vulnerability class: wallet private key and mnemonic theft via a disguised telemetry function
  • Weekly downloads: approximately 50,000
  • Dependent packages: 87
  • Malicious version downloads: 310
  • Disclosed by: Socket Security, July 9, 2026
  • CVE: none assigned as of publication

‍

Background

@injectivelabs/sdk-ts is the official TypeScript SDK for Injective Labs Cosmos-based Layer-1 chain. It is the standard library node services, exchanges, and wallets use to derive addresses, build transactions, and query the chain, which is why a compromise in its wallet-generation path has outsized reach across the Injective ecosystem. The package sits in the dependency tree of dozens of downstream Injective tooling packages, so teams can be exposed even when they never installed it directly.

‍

Table of contents

Related blogs

Pulling Apart Meta's Muse Security Model

Pulling Apart Meta's Muse Security Model

Muse isolates each agent and gates actions outside the model. That answers where the agent runs. Once you build on it, the question is what it can reach.

October 5, 2026

6

Your AI Guardrails Are Only as Real as Your Runtime Visibility

Your AI Guardrails Are Only as Real as Your Runtime Visibility

Most AI inventories describe intent, not execution. Why guardrails, agents and models have to be read from the running process to be governed.

October 4, 2026

7

Top 5 AI SAST Tools in 2026

Top 5 AI SAST Tools in 2026

AI SAST tools promise less noise and automatic fixes. Five tools compared on the six criteria that matter, and what the independent research shows.

September 11, 2026

15

Stop the waste.
Protect your environment with Kodem.

A Primer on Runtime Intelligence

See how Kodem reads what actually loads and executes in your running applications, and why that changes which findings matter.

See the Kodem platform

Kodem shows which vulnerabilities actually load and execute in your running applications, so your team works the risk that is real.

The State of the Application Security Workflow

This report aims to equip readers with actionable insights that can help future-proof their security programs. Kodem, the publisher of this report, purpose built a platform that bridges these gaps by unifying shift-left strategies with runtime monitoring and protection.

3D book mockup of Kodem's State of the Application Security Workflow 2025 report

Get real-time insights across the full stack…code, containers, OS, and memory

Watch how Kodem’s runtime security platform detects and blocks attacks before they cause damage. No guesswork. Just precise, automated protection.

Kodem issues list with a magnified view of insight icons: runtime, ingress, and exploitability
Combined author
Mahesh Babu
Publish date

0 min read

AI Security