A simple search leads me to this: https://github.com/anko/xkbcat
There isn't a real attack using it yet, only because attacking Desktop Linux is a really unprofitable endeavor (considering the marketshare, the ROI must be very low).
> To actually be safe while installing and running malicious applications you need extensive sandboxing
FWIW, X11 is unsandboxable unless you run a second X server on top of your current server [0]. Which is fine, but you need to consider that most, if not all sandboxing solutions on Linux that "newbs" use, like Flatpak, do not employ such technique when running sandboxed X11 applications.
The "security by default" behavior of Wayland limits the possible attack surface a lot, without requiring the end user to understand all the nitty details involved.
[0]: https://wiki.archlinux.org/title/Bubblewrap#Sandboxing_X11