{"schemaVersion":"guard-threat-campaign/v1","id":"HGTC-2026-INJECTIVE26","slug":"injective-sdk-wallet-key-exfiltration","title":"Injective SDK wallet-key exfiltration","aliases":["Injective SDK 1.20.21 compromise"],"summary":"Socket documented a compromised @injectivelabs/sdk-ts npm release that added fake telemetry behavior to sensitive key-derivation code and published related scoped packages pinned to the malicious version.","status":"published","severity":"critical","confidence":"high","uncertainty":"The reviewed report states that the malicious release was quickly contained, but downloadable artifacts and downstream exposure can vary. HOL does not infer victim losses from package download statistics.","firstObservedAt":"2026-06-08T18:06:00.000Z","lastObservedAt":"2026-07-09T00:00:00.000Z","publishedAt":"2026-08-09T11:30:00.000Z","reviewedAt":"2026-08-09T11:20:00.000Z","expiresAt":"2026-09-08T23:59:59.000Z","reviewer":"HOL Guard Research","sources":[{"id":"source:socket-injective","label":"Socket: compromised Injective SDK package","url":"https://socket.dev/blog/compromised-injective-sdk-npm-package","sourceType":"other_primary","observedAt":"2026-08-09T11:20:00.000Z"}],"artifacts":[{"id":"artifact:injective-sdk","artifactClass":"package","ecosystem":"npm","name":"@injectivelabs/sdk-ts","version":"1.20.21","defanged":true}],"indicators":[],"timeline":[{"id":"timeline:first-observed","occurredAt":"2026-06-08T18:06:00.000Z","eventType":"first_observed","summary":"Injective SDK wallet-key exfiltration was first observed in the reviewed source material.","sourceIds":["source:socket-injective"]},{"id":"timeline:disclosure","occurredAt":"2026-07-09T00:00:00.000Z","eventType":"disclosure","summary":"The reviewed source published or updated its defensive analysis and remediation guidance.","sourceIds":["source:socket-injective"]}],"coverage":[{"assertionId":"coverage:stable:codex","relationship":"partial","limitation":"Install-time review can help on eligible package actions, but the reported malicious behavior executed during library use; Guard does not claim universal mediation of arbitrary application code."}],"policies":[{"policyId":"policy:package-install-review","purpose":"Require review or explicit approval for new or changed dependency installation before an eligible package-manager action executes.","status":"available","limitation":"Coverage depends on the active Guard release, package manager, harness event surface, and local policy. It is not a guarantee that every dependency path is intercepted."}],"limitations":["Any secret material processed by an affected library version must be handled according to the incident source guidance; Guard cannot retroactively revoke exposed keys."],"correctionHref":"/guard/security/campaigns/injective-sdk-wallet-key-exfiltration/corrections"}