• About
  • FAQ
  • Contact Us
Newsletter
Crypto News
Advertisement
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • News
  • Market
  • Analysis
  • DeFi & NFTs
  • Guides
  • Tools
  • Flash
  • Insights
  • Subscribe
No Result
View All Result
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
  • News
  • Market
  • Analysis
  • DeFi & NFTs
  • Guides
  • Tools
  • Flash
  • Insights
  • Subscribe
No Result
View All Result
Crypto News
No Result
View All Result
Home Market

XRP Ledger developer kit compromised with backdoor to steal wallet private keys

admin by admin
April 25, 2025
in Market
0
XRP Ledger developer kit compromised with backdoor to steal wallet private keys
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter



Aikido Security disclosed a vulnerability in the XRP Ledger’s (XRPL) official JavaScript SDK, revealing that multiple compromised versions of the XRPL Node Package Manager (NPM) package were published to the registry starting April 21. 

The affected versions, v4.2.1 through v4.2.4 and v2.14.2, contained a backdoor capable of exfiltrating private keys, posing a severe risk to crypto wallets that relied on the software.

An NPM package is a reusable module for JavaScript and Node.js projects designed to simplify installation, updates, and removal.

According to Aikido Security, its automated threat monitoring platform flagged the anomaly at 8:53 PM UTC on April 21 when NPM user “mukulljangid” published five new versions of the XRPL package.

These releases did not match any tagged releases on the official GitHub repository, prompting immediate suspicion of a supply chain compromise.

Malicious code embedded in the wallet logic

Aikido’s analysis found that the compromised packages contained a function called checkValidityOfSeed, which made outbound calls to the newly registered and unverified domain 0x9c[.]xyz. 

The function was triggered during the instantiation of the wallet class, causing private keys to be silently transmitted when creating a wallet.

Early versions (v4.2.1 and v4.2.2) embedded the malicious code in the built JavaScript files. Subsequent versions (v4.2.3 and v4.2.4) introduced the backdoor into the TypeScript source files, followed by their compilation into production code. 

The attacker appeared to iterate on evasion techniques, shifting from manual JavaScript manipulation to deeper integration in the SDK’s build process.

The report stated that this package is used by hundreds of thousands of applications and websites, describing the event as a targeted attack against the crypto development infrastructure. 

The compromised versions also removed development tools such as prettier and scripts from the package.json file, further indicating deliberate tampering.

XRP Ledger Foundation and ecosystem response

The XRP Ledger Foundation acknowledged the issue in a public statement published via X on April 22. It stated:

“Earlier today, a security researcher from @AikidoSecurity identified a serious vulnerability in the xrpl npm package (v4.2.1–4.2.4 and v2.14.2). We are aware of the issue and are actively working on a fix. A detailed post-mortem will follow.”

Mark Ibanez, CTO of XRP Ledger-based Gen3 Games, said his team avoided the compromised package versions with a “bit of luck.”

He added: 

“Our package.json specified ‘xrpl’: ‘^4.1.0’, which means that, under normal circumstances, any compatible minor or patch version—including potentially compromised ones—could have been installed during development, builds, or deployments.”

However, Gen3 Games commits its pnpm-lock.yaml file to version control. This practice ensured that exact versions, not newly published ones, were installed during development and deployment.

Ibanez emphasized several practices to mitigate risks, such as always committing the “lockfile” to version control, using Performant NPM (PNPM) when possible, and avoiding the use of the caret (^) symbol in package.json to prevent unintended version upgrades.

The software developer kit maintained by Ripple and distributed through NPM receives over 140,000 downloads per week, with developers widely using it to build applications on the XRP Ledger. 

The XRP Ledger Foundation removed the affected versions from the NPM registry shortly after the disclosure. Still, it remains unknown how many users had integrated the compromised versions before the issue was flagged.

Mentioned in this article



#XRP #Ledger #developer #kit #compromised #backdoor #steal #wallet #private #keys

Related articles

Fast food giant Steak ‘n Shake launches Bitcoin payments, boosts financial efficiency

Fast food giant Steak ‘n Shake launches Bitcoin payments, boosts financial efficiency

May 27, 2025
Bo Hines declares the US won’t sell Bitcoin, seek endless accumulation for strategic reserve

Bo Hines declares the US won’t sell Bitcoin, seek endless accumulation for strategic reserve

May 27, 2025
Tags: and girls with unimaginable cruelty duringbackdoorbuilt javascript filescompromisedcrypto walletct strong peoplecto of xrp ledgerDeveloperdxy index which measures the dollarforced up to 400 000 peoplegalaxy digital glxy said it deepenedin btc derivatives and such anis used by hundreds of thousandsjson to prevent unintended versionKeyskitLedgermin aung hlaing who seizedmullin blamed the token crashpeople ldquo ofpotentially valuing the company at 4pritzker elon musk isPrivaterevealing that multiple compromised versions ofserious vulnerability in the xrplstealsupply chain compromisethe typescript source filesto crypto wallets thatto steal wallet private keystopics li ul p thursdayuncertainty rather than a well definedunion s multinational bloc have movedWalletwith developerXRPxrp ledger developeryear the sec approved spot bitcoin
Share76Tweet47

Related Posts

Fast food giant Steak ‘n Shake launches Bitcoin payments, boosts financial efficiency

Fast food giant Steak ‘n Shake launches Bitcoin payments, boosts financial efficiency

by admin
May 27, 2025
0

Fast food chain Steak ‘n Shake has expanded its payment options to include Bitcoin (BTC) at all of its locations...

Bo Hines declares the US won’t sell Bitcoin, seek endless accumulation for strategic reserve

Bo Hines declares the US won’t sell Bitcoin, seek endless accumulation for strategic reserve

by admin
May 27, 2025
0

Bo Hines told the 2025 Bitcoin Conference in Las Vegas on May 27 that the federal government will hold every...

Cetus seeks Sui community nod to unlock 2M to make users whole

Cetus seeks Sui community nod to unlock $162M to make users whole

by admin
May 27, 2025
0

Sui-based protocol Cetus said on May 27 that it can reimburse every user affected by its May 22 exploit if...

VanEck proposes mining royalty to fill US strategic Bitcoin reserve in a budget-neutral way

VanEck proposes mining royalty to fill US strategic Bitcoin reserve in a budget-neutral way

by admin
May 27, 2025
0

VanEck head of digital assets research Matthew Sigel called on US lawmakers to attach a royalty to domestic Bitcoin (BTC)...

SharpLink makes 5M Ethereum treasury plunge with Joseph Lubin’s guidance

SharpLink makes $425M Ethereum treasury plunge with Joseph Lubin’s guidance

by admin
May 27, 2025
0

SharpLink Gaming plans to establish a $425 million Ethereum (ETH) treasury under the guidance of Consensys CEO and Ethereum co-founder...

Load More
  • Trending
  • Comments
  • Latest
Bitcoin and Ethereum Stuck in Range, DOGE and XRP Gain

Bitcoin and Ethereum Stuck in Range, DOGE and XRP Gain

April 25, 2025
Saylor says Warren Buffett’s Berkshire Hathaway is Bitcoin of 20th century – Deep Insight

Saylor says Warren Buffett’s Berkshire Hathaway is Bitcoin of 20th century – Deep Insight

May 7, 2025
Amazon CEO on Crypto and NFTs, EPNS to Expand Beyond Ethereum + More News

Amazon CEO on Crypto and NFTs, EPNS to Expand Beyond Ethereum + More News

April 25, 2025
Why DeFi agents need a private brain

Why DeFi agents need a private brain

May 4, 2025
US Commodities Regulator Beefs Up Bitcoin Futures Review

US Commodities Regulator Beefs Up Bitcoin Futures Review

0
Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

0
India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

0
Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: 5.55

Bitcoin’s Main Rival Ethereum Hits A Fresh Record High: $425.55

0
ASIC Sues Former Blockchain Global Exec Over M in Unpaid Customer Claims

ASIC Sues Former Blockchain Global Exec Over $20M in Unpaid Customer Claims

May 28, 2025
Crypto czar Sacks says US could possibly ‘acquire more Bitcoin’

Crypto czar Sacks says US could possibly ‘acquire more Bitcoin’

May 28, 2025
Bitcoin Traders Eye New Highs by End of Summer; Ether Rises 3% on Treasury Optimism

Bitcoin Traders Eye New Highs by End of Summer; Ether Rises 3% on Treasury Optimism

May 28, 2025
Cetus Reveals Recovery Plan, Taps SUI for Bridge Loan

Cetus Reveals Recovery Plan, Taps SUI for Bridge Loan

May 28, 2025
  • About
  • FAQ
  • Contact Us
Call us: +1 23456 JEG THEME

© 2025 Btc04.com

No Result
View All Result
  • Home
  • News
  • Market
  • Analysis
  • DeFi & NFTs
  • Guides
  • Tools
  • Flash
  • Insights
  • Subscribe
  • Contact Us

© 2025 Btc04.com