Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Hackers use GitHub repository to host Amadey Malware and Data Stealers and bypass filters

Openai launches a general purpose agent with ChatGpt

Rivian will resume work at the Georgia factory, emails show

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Ripple’s XRPL.JS NPM package becomes a backdoo in the background, stealing private keys in major supply chain attacks
Identity

Ripple’s XRPL.JS NPM package becomes a backdoo in the background, stealing private keys in major supply chain attacks

userBy userApril 23, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

April 23, 2025Ravi LakshmananBlockchain/Cryptocurrency

Ripple's XRPL.JS NPM package now in the background

The Ripple Cryptocurrency NPM JavaScript library, named Xrpl.js, is compromised by unknown threat actors as part of a software supply chain attack designed to harvest and remove user private keys.

Malicious activity has been found to affect five different versions of packages: 4.2.1, 4.2.2, 4.2.3, 4.2.4, and 2.14.2. This issue is explained in versions 4.2.5 and 2.14.3.

Cybersecurity

Xrpl.js is a popular JavaScript API for interacting with the XRP Ledger blockchain, also known as the Ripple Protocol, a cryptocurrency platform launched by Ripple Labs in 2012. The package has been downloaded over 2.9 million times so far, attracting over 135,000 weekly downloads.

“The official XPRL (Ripple) NPM package was compromised by sophisticated attackers who could put in a backdoor and steal private cryptocurrency keys and access the cryptocurrency wallet.”

It is known that malicious code changes have been introduced from April 21, 2025 by a user named “Mukulljangid”. Threat actors introduce a new feature called CheckValiditivityOfseed, which is designed to send stolen information to external domains (“0x9c[.]xyz “).

It is worth noting that “Mukulljangid” is likely to belong to a Ripple employee. This indicates that the NPM account has been hacked and stopped the supply chain attack.

The attackers are said to have tried different ways of sneaking into the backdoor, trying to avoid detection, as evident by the various versions released in a short period of time. There is no evidence that the associated GitHub repository has become the background.

Cybersecurity

It’s not clear who is behind the attack, but it is believed that threat actors were able to steal the developer’s NPM access token and tamper with the library.

In light of the incident, users relying on the XRPL.JS library are advised to update their instances to the latest versions (4.2.5 and 2.14.3) to mitigate potential threats.

“This vulnerability lies in Xrpl.js, a JavaScript library that allows you to interact with XRP Ledger.” The XRP Ledger Foundation stated in an X post.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous Article‘Act of war’: What happened in Kashmir attack that killed 26 tourists? | Conflict News
Next Article How Pope Francis redefines the Church’s relations with Africa | Religious News
user
  • Website

Related Posts

Hackers use GitHub repository to host Amadey Malware and Data Stealers and bypass filters

July 17, 2025

Hackers exploit flaws in apache http server to deploy linuxsys cryptocurrency miner

July 17, 2025

Europol destroys Hacktivist Group linked to DDOS attacks against Ukraine

July 17, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Hackers use GitHub repository to host Amadey Malware and Data Stealers and bypass filters

Openai launches a general purpose agent with ChatGpt

Rivian will resume work at the Georgia factory, emails show

Boulevard raises $80 million to power the self-care boom driven by Botox and GLP-1 surges

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

BREAKING: TwinH Set to Revolutionize Legal Processes – Presented Today at ICEX Forum 2025

Building AGI: Zuckerberg Commits Billions to Meta’s Superintelligence Data Center Expansion

ICEX Forum 2025 Opens: FySelf’s TwinH Showcases AI Innovation

The Future of Process Automation is Here: Meet TwinH

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.