Tuesday, November 25, 2025
DIGESTWIRE
Contribute
CONTACT US
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Blog
  • Founders
No Result
View All Result
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Blog
  • Founders
No Result
View All Result
DIGESTWIRE
No Result
View All Result
Home Blockchain

XRP Ledger developer kit compromised with backdoor to steal wallet private keys

by DigestWire member
April 22, 2025
in Blockchain, Crypto Market, Cryptocurrency
0
XRP Ledger developer kit compromised with backdoor to steal wallet private keys
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Aikido Security disclosed a vulnerability in the XRP Ledger’s (XRPL) official JavaScript SDK, revealing that multiple compromised versions of the XRPL Node Package Manager (NPM) package were published to the registry starting April 21. 

The affected versions, v4.2.1 through v4.2.4 and v2.14.2, contained a backdoor capable of exfiltrating private keys, posing a severe risk to crypto wallets that relied on the software.

An NPM package is a reusable module for JavaScript and Node.js projects designed to simplify installation, updates, and removal.

According to Aikido Security, its automated threat monitoring platform flagged the anomaly at 8:53 PM UTC on April 21 when NPM user “mukulljangid” published five new versions of the XRPL package.

These releases did not match any tagged releases on the official GitHub repository, prompting immediate suspicion of a supply chain compromise.

Malicious code embedded in the wallet logic

Aikido’s analysis found that the compromised packages contained a function called checkValidityOfSeed, which made outbound calls to the newly registered and unverified domain 0x9c[.]xyz. 

The function was triggered during the instantiation of the wallet class, causing private keys to be silently transmitted when creating a wallet.

Early versions (v4.2.1 and v4.2.2) embedded the malicious code in the built JavaScript files. Subsequent versions (v4.2.3 and v4.2.4) introduced the backdoor into the TypeScript source files, followed by their compilation into production code. 

The attacker appeared to iterate on evasion techniques, shifting from manual JavaScript manipulation to deeper integration in the SDK’s build process.

The report stated that this package is used by hundreds of thousands of applications and websites, describing the event as a targeted attack against the crypto development infrastructure. 

The compromised versions also removed development tools such as prettier and scripts from the package.json file, further indicating deliberate tampering.

XRP Ledger Foundation and ecosystem response

The XRP Ledger Foundation acknowledged the issue in a public statement published via X on April 22. It stated:

“Earlier today, a security researcher from @AikidoSecurity identified a serious vulnerability in the xrpl npm package (v4.2.1–4.2.4 and v2.14.2). We are aware of the issue and are actively working on a fix. A detailed post-mortem will follow.”

Mark Ibanez, CTO of XRP Ledger-based Gen3 Games, said his team avoided the compromised package versions with a “bit of luck.”

He added: 

“Our package.json specified ‘xrpl’: ‘^4.1.0’, which means that, under normal circumstances, any compatible minor or patch version—including potentially compromised ones—could have been installed during development, builds, or deployments.”

However, Gen3 Games commits its pnpm-lock.yaml file to version control. This practice ensured that exact versions, not newly published ones, were installed during development and deployment.

Ibanez emphasized several practices to mitigate risks, such as always committing the “lockfile” to version control, using Performant NPM (PNPM) when possible, and avoiding the use of the caret (^) symbol in package.json to prevent unintended version upgrades.

The software developer kit maintained by Ripple and distributed through NPM receives over 140,000 downloads per week, with developers widely using it to build applications on the XRP Ledger. 

The XRP Ledger Foundation removed the affected versions from the NPM registry shortly after the disclosure. Still, it remains unknown how many users had integrated the compromised versions before the issue was flagged.

The post XRP Ledger developer kit compromised with backdoor to steal wallet private keys appeared first on CryptoSlate.

Read Entire Article
Tags: BlockchainCoin SurgesCryptoslate
Share30Tweet19
Next Post
DeFi Development Corp adds $11.5M SOL,  shares jump 12%

DeFi Development Corp adds $11.5M SOL, shares jump 12%

Schiff Criticizes Trump’s Rate Cut Idea, Says Transition to Manufacturing Economy Requires Higher Rates

Schiff Criticizes Trump’s Rate Cut Idea, Says Transition to Manufacturing Economy Requires Higher Rates

I’m Laughing At What Sebastian Stan Had To Say About Donald Trump Watching Him In “The Apprentice” Movie

I'm Laughing At What Sebastian Stan Had To Say About Donald Trump Watching Him In "The Apprentice" Movie

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

No Result
View All Result
Coins MarketCap Live Updates Coins MarketCap Live Updates Coins MarketCap Live Updates
ADVERTISEMENT

Highlights

Chelsea v Barcelona: Confirmed line-ups as Estevao goes head-to-head with Yamal

Man City v Bayer Leverkusen: Confirmed line-ups as Pep shuffles pack for UCL clash

Marseille v Newcastle: Confirmed line-ups as Magpies face familiar faces in France

David Beckham Wasn’t Nervous When He Was Knighted by King Charles III

Nicole Kidman Shares Rare Personal Update After Keith Urban Divorce

Jamie Lee Curtis, Jennifer Lopez, Famke Janssen and More!

Trending

LIVE – Marseille v Newcastle: Commentary, updates, goals and stats
Football

LIVE – Marseille v Newcastle: Commentary, updates, goals and stats

by DigestWire member
November 25, 2025
0

Newcastle visit Marseille tonight. Follow the action with our live commentary...

LIVE – Chelsea v Barcelona: Commentary, updates, goals and stats

LIVE – Chelsea v Barcelona: Commentary, updates, goals and stats

November 25, 2025
LIVE – Man City v Bayer Leverkusen: Commentary, updates, goals and stats

LIVE – Man City v Bayer Leverkusen: Commentary, updates, goals and stats

November 25, 2025
Chelsea v Barcelona: Confirmed line-ups as Estevao goes head-to-head with Yamal

Chelsea v Barcelona: Confirmed line-ups as Estevao goes head-to-head with Yamal

November 25, 2025
Man City v Bayer Leverkusen: Confirmed line-ups as Pep shuffles pack for UCL clash

Man City v Bayer Leverkusen: Confirmed line-ups as Pep shuffles pack for UCL clash

November 25, 2025
DIGEST WIRE

DigestWire is an automated news feed that utilizes AI technology to gather information from sources with varying perspectives. This allows users to gain a comprehensive understanding of different arguments and make informed decisions. DigestWire is dedicated to serving the public interest and upholding democratic values.

Privacy Policy     Terms and Conditions

Recent News

  • LIVE – Marseille v Newcastle: Commentary, updates, goals and stats November 25, 2025
  • LIVE – Chelsea v Barcelona: Commentary, updates, goals and stats November 25, 2025
  • LIVE – Man City v Bayer Leverkusen: Commentary, updates, goals and stats November 25, 2025

Categories

  • Blockchain
  • Blog
  • Breaking News
  • Business
  • Cricket
  • Crypto Market
  • Cryptocurrency
  • Defense
  • Entertainment
  • Football
  • Founders
  • Health Care
  • Opinion
  • Politics
  • Sports
  • Strange
  • Technology
  • UK News
  • Uncategorized
  • US News
  • World

© 2020-23 Digest Wire. All rights belong to their respective owners.

No Result
View All Result
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Blockchain
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Strange
  • Blog
  • Founders
  • Contribute!

© 2024 Digest Wire - All right reserved.

Privacy Policy   Terms and Conditions

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.