CryptoSpiel.com
No Result
View All Result
  • Home
  • Live Crypto Prices
  • Live ICO
  • Exchange
  • Crypto News
  • Bitcoin
  • Altcoins
  • Blockchain
  • Regulations
  • Trading
  • Scams
  • Home
  • Live Crypto Prices
  • Live ICO
  • Exchange
  • Crypto News
  • Bitcoin
  • Altcoins
  • Blockchain
  • Regulations
  • Trading
  • Scams
No Result
View All Result
CryptoSpiel.com
No Result
View All Result

XRP Ledger Foundation Flags JavaScript Security Risk—Update Required

April 23, 2025
in Crypto News
Reading Time: 3 mins read
A A
0
XRPL-based Wallet and C14 Integration Simplifies Crypto Transactions
0
SHARES
11
VIEWS
ShareShareShareShareShare
  • Blockchain security researcher from Alkido identified a serious vulnerability in the xrpl npm package v4.2.1-4.2.4 and v2.14.2.
  • This package is used by hundreds of thousands of applications and websites that steal private keys as soon as a Wallet object is instantiated.

On April 22, the XRP Ledger Foundation issued an urgent security warning regarding a critical vulnerability in its official JavaScript library, xrpl.js, that developers use to interact with the XRP Ledger blockchain. The vulnerability was identified as a sophisticated supply chain attack, in which malware code was inserted in some versions of the xrpl.js package that can undermine the security of cryptocurrency wallets utilizing this library.​ Aikido Intel, Aikido’s public threat feed that uses LLMs to monitor the public package managers, discovered the vulnerability.

The affected versions of xrpl.js, specifically v4.2.1 through v4.2.4 and v2.14.2, contained a backdoor function named checkValidityOfSeed. The function was designed to pilfer private keys by sending them to an external unauthorized domain when generating or operating with a wallet.

The malware was inserted by an individual using the NPM account “mukulljangid,” which published these tainted versions to the Node Package Manager (NPM) registry. An NPM package is a reusable module for Node.js and JavaScript applications that simplifies installation, updates, and uninstallation. These versions were not in sync with any release on the XRP Ledger Foundation’s GitHub repository, which immediately aroused suspicions among security researchers.

Impact Evaluation

The bug revealed a critical vulnerability to any application or service utilizing the compromised versions of xrpl.js because it could lead to unauthorized access to users’ private keys and subsequent loss of funds. Notably, the XRP Ledger blockchain and official GitHub repository were not impacted.

Other XRP-related projects, such as Xamans Wallet, XRPScan, First Ledger, and Gen3 Games, announced that they were not impacted by the breach, either by publishing safe versions of the library or utilizing other infrastructure. 

As a result of this, the XRP Ledger Foundation simultaneously deprecated all of the compromised versions of xrpl.js on NPM to avoid future downloads. The vulnerable versions of xrpl.js on NPM should be updated right away to prevent additional downloads. It released a patched version, v4.2.5, which eliminates the malicious code and restores secure functionality.

Developers and projects using the vulnerable versions of the xrpl.js library are advised to take immediate action to secure their systems and user funds. They are recommended to upgrade to the fixed release, xrpl.js v4.2.5, or downgrade to the stable and unaffected v2.14.3. Additionally, any exposed secrets or private keys are to be rotated right away. As an additional precaution, vulnerable master keys are to be deactivated and replaced with newly generated standard key pairs to ensure security and integrity.

With this in mind, XRP has broken through the key resistance level of $2.20, rising to $2.26 after a 7.71% increase in the last 24 hours. This price surge has been mirrored by an increase in trading, with daily volume increasing by 104.04% to $5.04 billion.


Recommended for you:


Credit: Source link

RELATED POSTS

Ripple CEO Says CLARITY Act Talks Near Breakthrough as Senate Standoff Eases

Argentina Reviews Phone Logs in LIBRA Case Linked to Javier Milei (Report)

Stabble Urges Users to Pull Liquidity After Alleged North Korean Hacker Link

Buy JNews
ADVERTISEMENT
ShareTweetSendPinShare
Previous Post

Bitcoin ETFs Record Largest Inflow Since January With $936 Million Funds Influx

Next Post

Qodo Revolutionizes Code Search Efficiency Using NVIDIA DGX Technology

Related Posts

Ripple CEO Says CLARITY Act Talks Near Breakthrough as Senate Standoff Eases
Crypto News

Ripple CEO Says CLARITY Act Talks Near Breakthrough as Senate Standoff Eases

April 14, 2026
Argentina Reviews Phone Logs in LIBRA Case Linked to Javier Milei (Report)
Crypto News

Argentina Reviews Phone Logs in LIBRA Case Linked to Javier Milei (Report)

April 8, 2026
Stabble Urges Users to Pull Liquidity After Alleged North Korean Hacker Link
Crypto News

Stabble Urges Users to Pull Liquidity After Alleged North Korean Hacker Link

April 8, 2026
Next Post
Nvidia Plans to add Innovation in the Metaverse with Software, Marketplace Deals

Qodo Revolutionizes Code Search Efficiency Using NVIDIA DGX Technology

Nvidia Plans to add Innovation in the Metaverse with Software, Marketplace Deals

NVIDIA Launches Secure AI General Availability with Enhanced Protection for Large Language Models

Recommended Stories

No Content Available

Popular Stories

  • Winklevoss Twins Continue Crypto Donation Spree With Another $1,000,000 in Bitcoin (BTC)

    Trader Says DeFi Altcoin Aave Witnessing Clear Trend Switch, Updates Forecast on Two Low-Cap Coins

    0 shares
    Share 0 Tweet 0
  • BlockDAG Races Toward $600M: Almost at $100M as Big Whales Join—Litecoin & Aptos News

    0 shares
    Share 0 Tweet 0
  • 16 Settlements Finalized in Two Years Indicate Heightened Regulatory Focus

    0 shares
    Share 0 Tweet 0
  • NVIDIA Launches GenAI-Perf for Optimizing Generative AI Model Performance

    0 shares
    Share 0 Tweet 0
  • Ethereum Whales Are Buying Three Gaming Altcoins As Bitcoin and Crypto Markets Bounce Back

    0 shares
    Share 0 Tweet 0
CryptoSpiel.com

This is an online news portal that aims to provide the latest crypto news, blockchain, regulations and much more stuff like that around the world. Feel free to get in touch with us!

What’s New Here!

  • Ripple CEO Says CLARITY Act Talks Near Breakthrough as Senate Standoff Eases
  • SEC Opens Proceedings on NYSE Proposal to List Grayscale Crypto ETF Options – Regulation Bitcoin News
  • Anthropic Reveals Claude Code Tool Design Philosophy Behind AI Agent Development

Subscribe Now

Loading
  • Live Crypto Prices
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2021 - cryptospiel.com - All rights reserved!

No Result
View All Result
  • Home
  • Live Crypto Prices
  • Live ICO
  • Exchange
  • Crypto News
  • Bitcoin
  • Altcoins
  • Blockchain
  • Regulations
  • Trading
  • Scams

© 2021 - cryptospiel.com - All rights reserved!

Please enter CoinGecko Free Api Key to get this plugin works.