{"type":"bundle","id":"bundle--f725fb2b-f10e-5dd7-9d0a-5bd1796ae05b","objects":[{"type":"campaign","spec_version":"2.1","id":"campaign--cbfe581d-3ab8-54e6-b68e-0fdbaea56f59","created":"2026-08-09T11:30:00.000Z","modified":"2026-08-09T11:20:00.000Z","name":"Injective SDK wallet-key exfiltration","description":"Socket documented a compromised @injectivelabs/sdk-ts npm release that added fake telemetry behavior to sensitive key-derivation code and published related scoped packages pinned to the malicious version.","aliases":["Injective SDK 1.20.21 compromise"],"first_seen":"2026-06-08T18:06:00.000Z","last_seen":"2026-07-09T00:00:00.000Z","objective":"Defensive public threat-intelligence record; see limitations and source references.","external_references":[{"source_name":"Socket: compromised Injective SDK package","url":"https://socket.dev/blog/compromised-injective-sdk-npm-package"}]}]}