• About
  • Landing Page
  • Buy JNews
SB Crypto Guru News- latest crypto news, NFTs, DEFI, Web3, Metaverse
  • HOME
  • BITCOIN
  • CRYPTO UPDATES
    • GENERAL
    • ALTCOINS
    • ETHEREUM
    • CRYPTO EXCHANGES
    • CRYPTO MINING
  • BLOCKCHAIN
  • NFT
  • DEFI
  • WEB3
  • METAVERSE
  • REGULATIONS
  • SCAM ALERT
  • ANALYSIS
No Result
View All Result
  • HOME
  • BITCOIN
  • CRYPTO UPDATES
    • GENERAL
    • ALTCOINS
    • ETHEREUM
    • CRYPTO EXCHANGES
    • CRYPTO MINING
  • BLOCKCHAIN
  • NFT
  • DEFI
  • WEB3
  • METAVERSE
  • REGULATIONS
  • SCAM ALERT
  • ANALYSIS
No Result
View All Result
SB Crypto Guru News- latest crypto news, NFTs, DEFI, Web3, Metaverse
No Result
View All Result

XRP Ledger developer kit compromised with backdoor to steal wallet private keys

SB Crypto Guru News by SB Crypto Guru News
April 22, 2025
in Scam Alert
0 0
0
XRP Ledger developer kit compromised with backdoor to steal wallet private keys



XRP Ledger developer kit compromised with backdoor to steal wallet private keys

Aikido Security disclosed a vulnerability in the XRP Ledger’s (XRPL) official JavaScript SDK, revealing that multiple compromised versions of the XRPL Node Package Manager (NPM) package were published to the registry starting April 21. 

The affected versions, v4.2.1 through v4.2.4 and v2.14.2, contained a backdoor capable of exfiltrating private keys, posing a severe risk to crypto wallets that relied on the software.

An NPM package is a reusable module for JavaScript and Node.js projects designed to simplify installation, updates, and removal.

According to Aikido Security, its automated threat monitoring platform flagged the anomaly at 8:53 PM UTC on April 21 when NPM user “mukulljangid” published five new versions of the XRPL package.

These releases did not match any tagged releases on the official GitHub repository, prompting immediate suspicion of a supply chain compromise.

Malicious code embedded in the wallet logic

Aikido’s analysis found that the compromised packages contained a function called checkValidityOfSeed, which made outbound calls to the newly registered and unverified domain 0x9c[.]xyz. 

The function was triggered during the instantiation of the wallet class, causing private keys to be silently transmitted when creating a wallet.

Early versions (v4.2.1 and v4.2.2) embedded the malicious code in the built JavaScript files. Subsequent versions (v4.2.3 and v4.2.4) introduced the backdoor into the TypeScript source files, followed by their compilation into production code. 

The attacker appeared to iterate on evasion techniques, shifting from manual JavaScript manipulation to deeper integration in the SDK’s build process.

The report stated that this package is used by hundreds of thousands of applications and websites, describing the event as a targeted attack against the crypto development infrastructure. 

The compromised versions also removed development tools such as prettier and scripts from the package.json file, further indicating deliberate tampering.

XRP Ledger Foundation and ecosystem response

The XRP Ledger Foundation acknowledged the issue in a public statement published via X on April 22. It stated:

“Earlier today, a security researcher from @AikidoSecurity identified a serious vulnerability in the xrpl npm package (v4.2.1–4.2.4 and v2.14.2). We are aware of the issue and are actively working on a fix. A detailed post-mortem will follow.”

Mark Ibanez, CTO of XRP Ledger-based Gen3 Games, said his team avoided the compromised package versions with a “bit of luck.”

He added: 

“Our package.json specified ‘xrpl’: ‘^4.1.0’, which means that, under normal circumstances, any compatible minor or patch version—including potentially compromised ones—could have been installed during development, builds, or deployments.”

However, Gen3 Games commits its pnpm-lock.yaml file to version control. This practice ensured that exact versions, not newly published ones, were installed during development and deployment.

Ibanez emphasized several practices to mitigate risks, such as always committing the “lockfile” to version control, using Performant NPM (PNPM) when possible, and avoiding the use of the caret (^) symbol in package.json to prevent unintended version upgrades.

The software developer kit maintained by Ripple and distributed through NPM receives over 140,000 downloads per week, with developers widely using it to build applications on the XRP Ledger. 

The XRP Ledger Foundation removed the affected versions from the NPM registry shortly after the disclosure. Still, it remains unknown how many users had integrated the compromised versions before the issue was flagged.

Mentioned in this article



Source link

Tags: BackdoorBitcoin NewsCompromisedCrypto NewsCrypto UpdatesdeveloperkeysKitLatest News on CryptoLedgerPrivateSB Crypto Guru NewsStealWalletXRP
Previous Post

Dogecoin Trader Who Nailed 300% Rally Says It’s About To Repeat

Next Post

Bitcoin’s Transformative Role As A Retirement Asset

Next Post
Bitcoin’s Transformative Role As A Retirement Asset

Bitcoin’s Transformative Role As A Retirement Asset

  • Trending
  • Comments
  • Latest
The Metaverse is Coming Back! – According to Meta

The Metaverse is Coming Back! – According to Meta

February 7, 2025
How to Get Token Prices with an RPC Node – Moralis Web3

How to Get Token Prices with an RPC Node – Moralis Web3

September 3, 2024
AI & Immersive Learning: Accelerating Skill Development with AI and XR

AI & Immersive Learning: Accelerating Skill Development with AI and XR

June 4, 2025
5 Proven XR and AI Training Use Cases for Enterprises

5 Proven XR and AI Training Use Cases for Enterprises

June 2, 2025
Meta Pumps a Further  Million into Horizon Metaverse

Meta Pumps a Further $50 Million into Horizon Metaverse

February 24, 2025
Samsung Unveils ‘Moohan’ to Compete with Quest, Vision Pro

Samsung Unveils ‘Moohan’ to Compete with Quest, Vision Pro

January 29, 2025
Why Bitcoin Summer 2025 Will Catch Everyone Off Guard: Analyst

Why Bitcoin Summer 2025 Will Catch Everyone Off Guard: Analyst

0
Solana (SOL) at Crossroads — Bounce Likely If 2 Remains Intact

Solana (SOL) at Crossroads — Bounce Likely If $142 Remains Intact

0
XRP Ledger payment transactions surges 430% in two years

XRP Ledger payment transactions surges 430% in two years

0
InComm Partners with NCR Atleos on Cardless Cash ATMs

InComm Partners with NCR Atleos on Cardless Cash ATMs

0
Big Beautiful Bill Passed Without Crypto Tax Exemption but Hope’s Not Lost

Big Beautiful Bill Passed Without Crypto Tax Exemption but Hope’s Not Lost

0
Hobbs Rejects New Attempt to Use Seized Crypto in Arizona

Hobbs Rejects New Attempt to Use Seized Crypto in Arizona

0
XRP Ledger payment transactions surges 430% in two years

XRP Ledger payment transactions surges 430% in two years

July 2, 2025
Why Bitcoin Summer 2025 Will Catch Everyone Off Guard: Analyst

Why Bitcoin Summer 2025 Will Catch Everyone Off Guard: Analyst

July 2, 2025
Big Beautiful Bill Passed Without Crypto Tax Exemption but Hope’s Not Lost

Big Beautiful Bill Passed Without Crypto Tax Exemption but Hope’s Not Lost

July 2, 2025
Hobbs Rejects New Attempt to Use Seized Crypto in Arizona

Hobbs Rejects New Attempt to Use Seized Crypto in Arizona

July 2, 2025
Crossmint and Visa Join Forces to Power AI-Driven Commerce

Crossmint and Visa Join Forces to Power AI-Driven Commerce

July 2, 2025
Solana (SOL) at Crossroads — Bounce Likely If 2 Remains Intact

Solana (SOL) at Crossroads — Bounce Likely If $142 Remains Intact

July 2, 2025
SB Crypto Guru News- latest crypto news, NFTs, DEFI, Web3, Metaverse

Find the latest Bitcoin, Ethereum, blockchain, crypto, Business, Fintech News, interviews, and price analysis at SB Crypto Guru News.

CATEGORIES

  • Altcoin
  • Analysis
  • Bitcoin
  • Blockchain
  • Crypto Exchanges
  • Crypto Updates
  • DeFi
  • Ethereum
  • Metaverse
  • Mining
  • NFT
  • Regulations
  • Scam Alert
  • Uncategorized
  • Web3

SITE MAP

  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

© 2025 JNews - Premium WordPress news & magazine theme by Jegtheme.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • HOME
  • BITCOIN
  • CRYPTO UPDATES
    • GENERAL
    • ALTCOINS
    • ETHEREUM
    • CRYPTO EXCHANGES
    • CRYPTO MINING
  • BLOCKCHAIN
  • NFT
  • DEFI
  • WEB3
  • METAVERSE
  • REGULATIONS
  • SCAM ALERT
  • ANALYSIS

© 2025 JNews - Premium WordPress news & magazine theme by Jegtheme.