Reviewed threat campaign

Injective SDK wallet-key exfiltration

Socket documented a compromised @injectivelabs/sdk-ts npm release that added fake telemetry behavior to sensitive key-derivation code and published related scoped packages pinned to the malicious version.

Severity criticalConfidence highReviewed 2026-08-09Expires 2026-09-08

Uncertainty

The reviewed report states that the malicious release was quickly contained, but downloadable artifacts and downstream exposure can vary. HOL does not infer victim losses from package download statistics.

Limitations

Timeline

  1. · Injective SDK wallet-key exfiltration was first observed in the reviewed source material.
  2. · The reviewed source published or updated its defensive analysis and remediation guidance.

Publication clock: 755.5 hours from reviewed disclosure timestamp to HOL publication; 12-hour critical target; historical backfill outside target.

Guard coverage and non-coverage

Defensive policy guidance

Sources