• News
    • Bitcoin
    • Altcoins
    • Blockchain
    • DeFi
    • Regulation
    • Scams
  • NFT
  • Metaverse
  • Analysis
  • Learn
  • Videos
  • Blogs
  • Market Cap
  • Shop
What's Hot

What Is Yield Farming in Crypto? A Beginner’s Guide to DeFi Income

2025-06-02

Lightning Network Is About to Explode!

2025-06-02

Bitcoin to $200k?! Latest 2025 BTC Price Predictions

2025-06-01

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

Facebook Twitter Instagram
Crypto Investor News Network
  • News
    • Bitcoin
    • Altcoins
    • Blockchain
    • DeFi
    • Regulation
    • Scams
  • NFT

    All Eyes on Art: Upcoming Collections to Watch the Week of February 4

    2025-02-05

    Creator of rabbit AI assistant has hidden NFT past

    2024-05-02

    Ethereum tops daily NFT sales at US$7 mln, ends weakest month of 2024

    2024-05-02

    Top NFT Airdrops and Giveaways for May 2024

    2024-05-02

    Casio Launches NFT Collection Celebrating 50th Anniversary

    2024-05-01
  • Metaverse

    Shib: The Metaverse – Part of the Expanding Shiba Inu Ecosystem

    2025-01-03

    Experience to Earn: Everdome’s Metaverse Frontier

    2024-12-30

    Beyond Bots: Meta Motivo and the Dawn of Humanlike Digital Life

    2024-12-13

    Exploring NetVRk: What Is Behind This AI-Driven Virtual Universe?

    2024-10-28

    Council of Europe Highlights Metaverse’s Impact on Privacy and Democracy

    2024-09-05
  • Analysis

    Crypto Exchange Coinbase Lists New DeFi Altcoin Project Built on Base Blockchain

    2023-12-13

    Ethereum Price Bears Keep Pushing, Why Decline Isn’t Over Yet

    2023-12-13

    Trader Bullish on Cosmos (ATOM), Says One Dogecoin Rival Setting Up for Next Leg Up – Here’s His Outlook

    2023-12-13

    AVAX Price Pumps 50% and Dumps 15%, Why Uptrend Is Still Strong

    2023-12-13

    Top Trader Predicts Parabolic Rally for Solana Competitor – Here’s His Upside Target

    2023-12-13
  • Learn

    What Is Yield Farming in Crypto? A Beginner’s Guide to DeFi Income

    2025-06-02

    What Is Asset Tokenization? Types, Why It Matters Now [2025]

    2025-05-30

    What Is Crypto Margin Trading? A Beginner-Friendly Guide to Leverage

    2025-05-26

    What Is Circulating Supply in Crypto? A Beginner’s Guide to Token Supply

    2025-05-23

    What Is a DEX? How DEXs Work and Why They Matter

    2025-05-21
  • Videos

    Lightning Network Is About to Explode!

    2025-06-02

    Bitcoin to $200k?! Latest 2025 BTC Price Predictions

    2025-06-01

    My Last Day at Bitcoin 2025 Conference

    2025-05-31

    Bitcoin Summer Doldrums Ahead? 🌞📉 Or Fireworks Coming?🔥

    2025-05-31

    Bitcoin Is Preparing For A Massive Move According To This Legendary Analyst

    2025-05-31
  • Blogs
  • Market Cap
  • Shop
Facebook Twitter Instagram TikTok
Crypto Investor News Network
Home»Scams»XRP Ledger developer kit compromised with backdoor to steal wallet private keys
Scams

XRP Ledger developer kit compromised with backdoor to steal wallet private keys

2025-04-22No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
XRP Ledger developer kit compromised with backdoor to steal wallet private keys
Share
Facebook Twitter LinkedIn Pinterest Email

Aikido Security disclosed a vulnerability in the XRP Ledger’s (XRPL) official JavaScript SDK, revealing that multiple compromised versions of the XRPL Node Package Manager (NPM) package were published to the registry starting April 21. 

The affected versions, v4.2.1 through v4.2.4 and v2.14.2, contained a backdoor capable of exfiltrating private keys, posing a severe risk to crypto wallets that relied on the software.

An NPM package is a reusable module for JavaScript and Node.js projects designed to simplify installation, updates, and removal.

According to Aikido Security, its automated threat monitoring platform flagged the anomaly at 8:53 PM UTC on April 21 when NPM user “mukulljangid” published five new versions of the XRPL package.

These releases did not match any tagged releases on the official GitHub repository, prompting immediate suspicion of a supply chain compromise.

Malicious code embedded in the wallet logic

Aikido’s analysis found that the compromised packages contained a function called checkValidityOfSeed, which made outbound calls to the newly registered and unverified domain 0x9c[.]xyz. 

The function was triggered during the instantiation of the wallet class, causing private keys to be silently transmitted when creating a wallet.

Early versions (v4.2.1 and v4.2.2) embedded the malicious code in the built JavaScript files. Subsequent versions (v4.2.3 and v4.2.4) introduced the backdoor into the TypeScript source files, followed by their compilation into production code. 

The attacker appeared to iterate on evasion techniques, shifting from manual JavaScript manipulation to deeper integration in the SDK’s build process.

The report stated that this package is used by hundreds of thousands of applications and websites, describing the event as a targeted attack against the crypto development infrastructure. 

See also  Crypto Trader Behind $110,000,000 Mango Markets Exploit Convicted on Fraud Charges

The compromised versions also removed development tools such as prettier and scripts from the package.json file, further indicating deliberate tampering.

XRP Ledger Foundation and ecosystem response

The XRP Ledger Foundation acknowledged the issue in a public statement published via X on April 22. It stated:

“Earlier today, a security researcher from @AikidoSecurity identified a serious vulnerability in the xrpl npm package (v4.2.1–4.2.4 and v2.14.2). We are aware of the issue and are actively working on a fix. A detailed post-mortem will follow.”

Mark Ibanez, CTO of XRP Ledger-based Gen3 Games, said his team avoided the compromised package versions with a “bit of luck.”

He added: 

“Our package.json specified ‘xrpl’: ‘^4.1.0’, which means that, under normal circumstances, any compatible minor or patch version—including potentially compromised ones—could have been installed during development, builds, or deployments.”

However, Gen3 Games commits its pnpm-lock.yaml file to version control. This practice ensured that exact versions, not newly published ones, were installed during development and deployment.

Ibanez emphasized several practices to mitigate risks, such as always committing the “lockfile” to version control, using Performant NPM (PNPM) when possible, and avoiding the use of the caret (^) symbol in package.json to prevent unintended version upgrades.

The software developer kit maintained by Ripple and distributed through NPM receives over 140,000 downloads per week, with developers widely using it to build applications on the XRP Ledger. 

The XRP Ledger Foundation removed the affected versions from the NPM registry shortly after the disclosure. Still, it remains unknown how many users had integrated the compromised versions before the issue was flagged.

See also  Hacker With $42,000,000,000 in Wallet Exploits Interoperability Platform Poly Network
Mentioned in this article
BACKDOOR Compromised developer Keys Kit Ledger Private Steal Wallet XRP
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

US Treasury sanctions Philippines tech firm over aiding $200 million pig butchering spree

2025-05-30

Trader loses $2.5M USDT after falling for address poisoning scam twice

2025-05-26

Creator of over 100 memecoins says rug pulls are the ‘easiest way to make money’

2025-05-18

Jan 2024 SEC’s X account hacker got 14 months in prison for cyber fraud

2025-05-17
Add A Comment

Leave A Reply Cancel Reply

Top Posts
Bitcoin

I asked ChatGPT whether Bitcoin will touch $35k soon

2023-06-25

Disclaimer: The information presented does not constitute financial, investment, trading, or other types of advice…

Blockchain

What Is Proof-of-Stake (PoS)? The Investor’s Guide

2023-04-20

Blockchain Proof-of-stake is a type of blockchain consensus mechanism that evaluates the crypto stake of…

Videos

Ethereum Spot ETFs To Be Approved?

2024-05-21

Join the private Bitcoin forum: https://www.bitcoinuniversity.com/bitcoin-forum In this video, I discuss the increased probability of…

Subscribe to Updates

Get the latest news and Update from CINN about Crypto, Metaverse and NFT.

Editors Picks

What Is Yield Farming in Crypto? A Beginner’s Guide to DeFi Income

2025-06-02

Lightning Network Is About to Explode!

2025-06-02

Bitcoin to $200k?! Latest 2025 BTC Price Predictions

2025-06-01

My Last Day at Bitcoin 2025 Conference

2025-05-31
Crypto Investor News Network
Facebook Twitter Instagram TikTok
  • Contact
  • Terms & Conditions
  • Privacy Policy
  • DMCA
  • Disclouser
© 2025 - All rights are reserved.

Type above and press Enter to search. Press Esc to cancel.

bitcoin
Bitcoin (BTC) $ 104,936.12
ethereum
Ethereum (ETH) $ 2,618.87
tether
Tether (USDT) $ 1.00
xrp
XRP (XRP) $ 2.24
bnb
BNB (BNB) $ 667.38
solana
Solana (SOL) $ 156.14
usd-coin
USDC (USDC) $ 1.00
dogecoin
Dogecoin (DOGE) $ 0.192616
tron
TRON (TRX) $ 0.272014
cardano
Cardano (ADA) $ 0.68817
bitcoin
Bitcoin (BTC) $ 104,936.12
ethereum
Ethereum (ETH) $ 2,618.87
tether
Tether (USDT) $ 1.00
xrp
XRP (XRP) $ 2.24
bnb
BNB (BNB) $ 667.38
solana
Solana (SOL) $ 156.14
usd-coin
USDC (USDC) $ 1.00
dogecoin
Dogecoin (DOGE) $ 0.192616
tron
TRON (TRX) $ 0.272014
cardano
Cardano (ADA) $ 0.68817