Close Menu
  • News
    • Bitcoin
    • Altcoins
    • DeFi
    • Regulation
    • Market Cap
    • Web 3
    • Scam
  • Blockchain
  • NFT
  • Metaverse
  • Analysis
  • Learn
  • Blog
  • Contact
    • Tech7685@gmail.com
What's Hot

Bitcoin Golden Cross Pattern says that the crash up to $ 100,000 is normal – what to expect afterwards

2025-06-07

US Treasury abruptly buys $ 10,000,000,000 from his own fault in mass, historical treasury -backkoop

2025-06-07

Vera integrates Cheqd’s decentralized identity stack to enable safe B2B communication

2025-06-07
Facebook X (Twitter) Instagram
  • Contact
  • Terms & Conditions
  • Privacy Policy
  • DMCA
  • Advertise
  • BitcoinPlatform.com
Facebook X (Twitter) Instagram
Free Cryptocurrency – Bitcoin | Altcoins | Blockchain | News Stories Updated Daily
  • News
    • Bitcoin
    • Altcoins
    • DeFi
    • Regulation
    • Market Cap
    • Web 3
    • Scam
  • Blockchain

    Vera integrates Cheqd’s decentralized identity stack to enable safe B2B communication

    2025-06-07

    Kima works together with Alibaba Cloud to provide Web3 Finance infrastructure

    2025-06-07

    Blazpay forges new collaboration with Depin Union to expand decentralized infrastructure

    2025-06-07

    RWA Inc and Aano Invest launch tokenized Real Estate for global investors

    2025-06-07

    Polyhedra network launches ZKPYTORCH, which may improve the scalability of Ethereum and AI

    2025-06-06
  • NFT

    Song A Day Creator tells ‘Tax Nightmare’ after making millions of NFT Sale

    2025-06-06

    Trump Family touches Magic Eden with cease-and-desists about crypto-wallet plans: Bloomberg

    2025-06-05

    From color as theory to generative art with NFTs

    2025-06-05

    Yuga Labs throws NFT icons while it doubles on monkeys and others.

    2025-06-04

    Trump Deepfake calls for Velociraptors on Border Patrol, charges 1.2 m view

    2025-06-03
  • Metaverse

    Shib: The Metaverse – Part of the expanding Shiba Inu ecosystem

    2025-01-03

    Experience to Earn: Everdome’s Metaverse Frontier

    2024-12-30

    Beyond Bots: Meta Motivo and the Dawn of Human Digital Life

    2024-12-13

    Exploring NetVRk: What’s Behind This AI-Powered Virtual Universe?

    2024-10-28

    Council of Europe emphasizes the impact of Metaverse on privacy and democracy

    2024-09-05
  • Analysis

    JPMorgan Chase says that the American markets climb ‘Wall of Carrect’ to new heights of all time-with the most important sector as a second wind

    2025-06-07

    Can bulls defend this critical level of support?

    2025-06-07

    Wall Street Contrarian Jim Chanos reveals Big Shorts, says that in 30 months he increased by 7,961% that has risen by 7,961%

    2025-06-07

    XRP -Golf Structure predicts Wilde Fluctuations on its way to $ 4 Ath

    2025-06-07

    Gemini files confidential IPO concept as Shares of Circle Register a new of all time near $ 124

    2025-06-06
  • Learn

    What Is Crypto Staking? A Beginner-Friendly Guide

    2025-06-05

    What Are Liquidity Pools? A Beginner’s Guide

    2025-06-05

    What Is Yield Farming and How Does It Work?

    2025-06-02

    What Is Asset Tokenization? How It Works and Why It’s Important

    2025-05-30

    What Is DeFi 2.0 and Why It Matters

    2025-05-27
  • Blog
  • Contact
    • Tech7685@gmail.com
Free Cryptocurrency – Bitcoin | Altcoins | Blockchain | News Stories Updated Daily
Home»Scam»XRP Ledger Developer Kit compromised with back door to steal the wallet private keys
XRP Ledger Developer Kit compromised with back door to steal the wallet private keys
Scam

XRP Ledger Developer Kit compromised with back door to steal the wallet private keys

2025-04-22No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Aikido security a vulnerability announced In the official JavaScript SDK of the XRP Ledger (XRPL), they reveal that several compromised versions of the XRPL Node Package Manager (NPM) package were published to the register from 21 April.

The affected versions, V4.2.1 to V4.2.4 and V2.14.2, contain a back door that was able to exfil private keys, with a serious risk for crypto portfolios dependent on the software.

An NPM package is a reusable module for JavaScript- and Node.JS projects that are designed to simplify the installation, updates and removal.

According to Aikido Security, the automated threat monitoring platform De Anomalie marked at 8:53 pm UTC on April 21 when NPM user “Mukulljangid” published five new versions of the XRPL package.

These releases did not correspond to tagged releases on the official Github repository, which led to an immediate suspicion of a compromise for supply chain.

Malignant code embedded in the wallet -logic

The analysis of Aikido showed that the compromised packages contain a function called Checkvalidityofseed, which caused outgoing calls to the newly registered and non -rewarded domain 0x9c[.]XYZ.

The function was activated during the instantiation of the wallet class, so that private keys are silently transferred when making a wallet.

Early versions (V4.2.1 and V4.2.2) have embedded the malicious code in the built JavaScript files. Subsequent versions (V4.2.3 and V4.2.4) introduced the back door to the TypeScript Sources Sources, followed by their compilation in production code.

The attacker appeared to repeat about avoidance techniques, shifted from manual Javascript manipulation to deeper integration into the construction process of the SDK.

See also  Sec Mulls or XRP A merchandise is in the midst of lawsuits with negotiations with Ripple: report

The report stated that this package is used by hundreds of thousands of applications and websites, which describes the event as a targeted attack on the crypto development infrastructure.

The compromised versions also removed development tools such as nicer and scripts from the package.json file, which further indicate that intentional tampering.

XRP Ledger Foundation and Ecosystem Response

The XRP Ledger Foundation recognized The issue in a public statement published via X on April 22. It explained:

“Earlier today, a security investigator of @aikidosis security identified a serious vulnerability in the XRPL NPM package (V4.2.1–4.2.4 and V2.14.2). We are aware of the problem and work active in a solution. A detailed post-mortem will follow.”

Mark Ibanez, CTO from XRP Ledger-based Gen3 games, said that his team avoided the compromised package versions with a “little luck”.

He added:

“Our package.json has specified ‘XRPL’: ‘^4.1.0’, which means that, under normal circumstances, any compatible small or patch version – including possible compromised – may be installed during development, builds or implementations.”

Gen3 games, however, commit his PNPM-Lock.yaml file to version management. This practice ensured that exact versions, not newly published, were installed during development and implementation.

IBANEZ emphasized various practices to reduce risks, as always committing the “Lockfile” for version management, with the help of performance NPM (PNPM) if possible, and avoiding the use of the caret (^) -symbol in package.json to prevent unintended version -upgrades.

The software developer kit that is maintained by Ripple and distributed via NPM receives more than 140,000 downloads per week, whereby developers use it on a large scale to build applications on the XRP whides.

See also  XRP Short Traders Face Massive Losses While Ripple Scores Gain From SEC

The XRP Ledger Foundation removed the affected versions from the NPM register shortly after the disclosure. Yet it remains unknown how many users had integrated the compromised versions before the problem was marked.

State in this article

Source link

Compromised developer door Keys Kit Ledger Private steal Wallet XRP
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

XRP -Golf Structure predicts Wilde Fluctuations on its way to $ 4 Ath

2025-06-07

Trump Family-Backed World Liberty Financial sends Stakes-and-Head to unauthorized wallet: report

2025-06-06

XRP -price sends mixed signals after 4 green daily closures, crash or rally?

2025-06-06

Bitcoin wallet Creation raises 6 months, but traders sit back: why?

2025-06-05
Add A Comment

Comments are closed.

Top Posts

Justin Bieber’s Hit Song Turned into Royalty-Sharing NFT

2023-09-06

Top fund manager shares his prospects

2025-01-01

Coinbase Delisting sends the move of the movement to the all time low in the middle of the market scandal

2025-05-02
Editors Picks

Bitcoin Reclaims $28.2k, Whales Show Excitement By…

2023-05-29

VanEck predicts Solana could reach 50% of Ethereum’s market cap, targeting $330 per SOL

2024-09-25

$18,900,000,000 in US Treasuries Dumped by BRICS Members China, Brazil, India and UAE in One Month

2023-09-23

A new look at an old problem

2023-11-01
About
About

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Cryptocurrencies, Defi, NFT, Metaverse and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Bitcoin Golden Cross Pattern says that the crash up to $ 100,000 is normal – what to expect afterwards

US Treasury abruptly buys $ 10,000,000,000 from his own fault in mass, historical treasury -backkoop

Vera integrates Cheqd’s decentralized identity stack to enable safe B2B communication

Get Informed

Subscribe to Updates

Get the latest news and Update from Free.cc about Crypto, Metaverse, NFT and more.

  • Contact
  • Terms & Conditions
  • Privacy Policy
  • DMCA
  • Advertise
  • BitcoinPlatform.com
© 2025 Free.cc - All rights reserved. Contact: info@free.cc

Type above and press Enter to search. Press Esc to cancel.

  • bitcoinBitcoin(BTC)$102,551.86-2.50%
  • ethereumEthereum(ETH)$2,452.25-6.77%
  • tetherTether USDt(USDT)$1.000.02%
  • rippleXRP(XRP)$2.13-3.79%
  • binancecoinBNB(BNB)$639.94-4.14%
  • solanaSolana(SOL)$147.00-4.43%
  • usd-coinUSDC(USDC)$1.000.03%
  • tronTRON(TRX)$0.2768791.19%
  • dogecoinDogecoin(DOGE)$0.174677-8.27%
  • cardanoCardano(ADA)$0.64-6.09%
  • hyperliquidHyperliquid(HYPE)$34.51-2.79%
  • suiSui(SUI)$2.98-6.68%
  • chainlinkChainlink(LINK)$13.15-5.49%
  • stellarStellar(XLM)$0.260160-2.81%
  • unus-sed-leoUNUS SED LEO(LEO)$8.77-1.92%
  • avalanche-2Avalanche(AVAX)$19.18-5.41%
  • bitcoin-cashBitcoin Cash(BCH)$383.77-5.06%
  • the-open-networkToncoin(TON)$3.07-3.82%
  • shiba-inuShiba Inu(SHIB)$0.000012-5.71%
  • hedera-hashgraphHedera(HBAR)$0.164021-2.83%
  • litecoinLitecoin(LTC)$84.13-4.89%
  • polkadotPolkadot(DOT)$3.90-3.67%
  • moneroMonero(XMR)$319.470.56%
  • ethena-usdeEthena USDe(USDE)$1.00-0.02%
  • daiDai(DAI)$1.000.02%
  • bitget-tokenBitget Token(BGB)$4.58-3.28%
  • piPi(PI)$0.62-4.51%
  • pepePepe(PEPE)$0.000011-10.04%
  • uniswapUniswap(UNI)$6.01-5.44%
  • aaveAave(AAVE)$246.59-6.92%
  • bittensorBittensor(TAO)$361.16-5.32%
  • okbOKB(OKB)$49.93-0.30%
  • crypto-com-chainCronos(CRO)$0.098089-2.38%
  • aptosAptos(APT)$4.57-5.24%
  • nearNEAR Protocol(NEAR)$2.30-6.61%
  • internet-computerInternet Computer(ICP)$4.93-6.93%
  • ethereum-classicEthereum Classic(ETC)$16.51-4.90%
  • ondo-financeOndo(ONDO)$0.79-4.84%
  • gatechain-tokenGateToken(GT)$18.62-2.92%
  • usd1World Liberty Financial USD(USD1)$1.000.04%
  • kaspaKaspa(KAS)$0.082182-1.92%
  • mantleMantle(MNT)$0.64-4.45%
  • polygon-ecosystem-tokenPOL (prev. MATIC)(POL)$0.203093-6.07%
  • vechainVeChain(VET)$0.022894-4.12%
  • official-trumpOFFICIAL TRUMP(TRUMP)$9.75-10.96%
  • render-tokenRender(RENDER)$3.63-4.62%
  • ethenaEthena(ENA)$0.291607-8.02%
  • artificial-superintelligence-allianceArtificial Superintelligence Alliance(FET)$0.72-10.09%
  • worldcoin-wldWorldcoin(WLD)$1.05-7.67%
  • filecoinFilecoin(FIL)$2.41-6.89%
  • bitcoinBitcoin(BTC)$102,551.86-2.50%
  • ethereumEthereum(ETH)$2,452.25-6.77%
  • tetherTether USDt(USDT)$1.000.02%
  • rippleXRP(XRP)$2.13-3.79%
  • binancecoinBNB(BNB)$639.94-4.14%
  • solanaSolana(SOL)$147.00-4.43%
  • usd-coinUSDC(USDC)$1.000.03%
  • tronTRON(TRX)$0.2768791.19%
  • dogecoinDogecoin(DOGE)$0.174677-8.27%
  • cardanoCardano(ADA)$0.64-6.09%
  • hyperliquidHyperliquid(HYPE)$34.51-2.79%
  • suiSui(SUI)$2.98-6.68%
  • chainlinkChainlink(LINK)$13.15-5.49%
  • stellarStellar(XLM)$0.260160-2.81%
  • unus-sed-leoUNUS SED LEO(LEO)$8.77-1.92%
  • avalanche-2Avalanche(AVAX)$19.18-5.41%
  • bitcoin-cashBitcoin Cash(BCH)$383.77-5.06%
  • the-open-networkToncoin(TON)$3.07-3.82%
  • shiba-inuShiba Inu(SHIB)$0.000012-5.71%
  • hedera-hashgraphHedera(HBAR)$0.164021-2.83%
  • litecoinLitecoin(LTC)$84.13-4.89%
  • polkadotPolkadot(DOT)$3.90-3.67%
  • moneroMonero(XMR)$319.470.56%
  • ethena-usdeEthena USDe(USDE)$1.00-0.02%
  • daiDai(DAI)$1.000.02%
  • bitget-tokenBitget Token(BGB)$4.58-3.28%
  • piPi(PI)$0.62-4.51%
  • pepePepe(PEPE)$0.000011-10.04%
  • uniswapUniswap(UNI)$6.01-5.44%
  • aaveAave(AAVE)$246.59-6.92%
  • bittensorBittensor(TAO)$361.16-5.32%
  • okbOKB(OKB)$49.93-0.30%
  • crypto-com-chainCronos(CRO)$0.098089-2.38%
  • aptosAptos(APT)$4.57-5.24%
  • nearNEAR Protocol(NEAR)$2.30-6.61%
  • internet-computerInternet Computer(ICP)$4.93-6.93%
  • ethereum-classicEthereum Classic(ETC)$16.51-4.90%
  • ondo-financeOndo(ONDO)$0.79-4.84%
  • gatechain-tokenGateToken(GT)$18.62-2.92%
  • usd1World Liberty Financial USD(USD1)$1.000.04%
  • kaspaKaspa(KAS)$0.082182-1.92%
  • mantleMantle(MNT)$0.64-4.45%
  • polygon-ecosystem-tokenPOL (prev. MATIC)(POL)$0.203093-6.07%
  • vechainVeChain(VET)$0.022894-4.12%
  • official-trumpOFFICIAL TRUMP(TRUMP)$9.75-10.96%
  • render-tokenRender(RENDER)$3.63-4.62%
  • ethenaEthena(ENA)$0.291607-8.02%
  • artificial-superintelligence-allianceArtificial Superintelligence Alliance(FET)$0.72-10.09%
  • worldcoin-wldWorldcoin(WLD)$1.05-7.67%
  • filecoinFilecoin(FIL)$2.41-6.89%