VDB

GCVE-110-OSM-2026-9211

GCVE-110-OSM-2026-9211
Advisory PublishedCVSS 9.6/10
Vulnetix · Advisory published July 8, 2026
`@injectivelabs/wallet-cosmos@1.20.21` is one of 17 packages in the `@injectivelabs` ecosystem that pinned `@injectivelabs/sdk-ts@1.20.21` as a dependency, transitively delivering the malicious payload to downstream consumers. The package receives approximately 1,714 weekly downloads. The malicious code resides entirely in `sdk-ts` — see https://opensourcemalware.com/npm/@injectivelabs/sdk-ts for full technical details. The other affected packages in this ecosystem are: @injectivelabs/utils, @injectivelabs/networks, @injectivelabs/ts-types, @injectivelabs/exceptions, @injectivelabs/wallet-base, @injectivelabs/wallet-core, @injectivelabs/wallet-private-key, @injectivelabs/wallet-evm, @injectivelabs/wallet-trezor, @injectivelabs/wallet-cosmostation, @injectivelabs/wallet-ledger, @injectivelabs/wallet-wallet-connect, @injectivelabs/wallet-magic, @injectivelabs/wallet-strategy, @injectivelabs/wallet-turnkey, @injectivelabs/wallet-cosmos-strategy (all version 1.20.21). Safe action: upgrade to 1.20.23 or later and immediately rotate any cryptocurrency credentials (mnemonic phrases, private keys) processed while the compromised version was installed. Payload resides in `@injectivelabs/sdk-ts@1.20.21`. See https://opensourcemalware.com/npm/@injectivelabs/sdk-ts for full technical details including IOCs, exfiltration endpoint, and affected file hashes.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknown@injectivelabs/wallet-cosmos1.20.21 (affected)

Browse GCVE Records

75,823 records in the GCVE database · Updated August 3, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›