Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Bitcoin above $78K, ETH, SOL, DOGE higher as Senate clears Clarity Act yield hurdle

May 2, 2026

Ex SEC advisor joins KAST as stablecoin policy race heats up

May 2, 2026

The GENIUS Act opened the door for stablecoins, but regulators want to narrow it

May 2, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»XRP Ledger developer kit compromised with backdoor to steal wallet private keys
XRP Ledger developer kit compromised with backdoor to steal wallet private keys
Security and Privacy

XRP Ledger developer kit compromised with backdoor to steal wallet private keys

April 22, 20253 Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Aikido Security disclosed a vulnerability in the XRP Ledger’s (XRPL) official JavaScript SDK, revealing that multiple compromised versions of the XRPL Node Package Manager (NPM) package were published to the registry starting April 21. 

The affected versions, v4.2.1 through v4.2.4 and v2.14.2, contained a backdoor capable of exfiltrating private keys, posing a severe risk to crypto wallets that relied on the software.

An NPM package is a reusable module for JavaScript and Node.js projects designed to simplify installation, updates, and removal.

According to Aikido Security, its automated threat monitoring platform flagged the anomaly at 8:53 PM UTC on April 21 when NPM user “mukulljangid” published five new versions of the XRPL package.

These releases did not match any tagged releases on the official GitHub repository, prompting immediate suspicion of a supply chain compromise.

Malicious code embedded in the wallet logic

Aikido’s analysis found that the compromised packages contained a function called checkValidityOfSeed, which made outbound calls to the newly registered and unverified domain 0x9c[.]xyz. 

The function was triggered during the instantiation of the wallet class, causing private keys to be silently transmitted when creating a wallet.

Early versions (v4.2.1 and v4.2.2) embedded the malicious code in the built JavaScript files. Subsequent versions (v4.2.3 and v4.2.4) introduced the backdoor into the TypeScript source files, followed by their compilation into production code. 

The attacker appeared to iterate on evasion techniques, shifting from manual JavaScript manipulation to deeper integration in the SDK’s build process.

The report stated that this package is used by hundreds of thousands of applications and websites, describing the event as a targeted attack against the crypto development infrastructure. 

See also  Wells Fargo XRP Forecast Predicts Asset Could Reach $500

The compromised versions also removed development tools such as prettier and scripts from the package.json file, further indicating deliberate tampering.

XRP Ledger Foundation and ecosystem response

The XRP Ledger Foundation acknowledged the issue in a public statement published via X on April 22. It stated:

“Earlier today, a security researcher from @AikidoSecurity identified a serious vulnerability in the xrpl npm package (v4.2.1–4.2.4 and v2.14.2). We are aware of the issue and are actively working on a fix. A detailed post-mortem will follow.”

Mark Ibanez, CTO of XRP Ledger-based Gen3 Games, said his team avoided the compromised package versions with a “bit of luck.”

He added: 

“Our package.json specified ‘xrpl’: ‘^4.1.0’, which means that, under normal circumstances, any compatible minor or patch version—including potentially compromised ones—could have been installed during development, builds, or deployments.”

However, Gen3 Games commits its pnpm-lock.yaml file to version control. This practice ensured that exact versions, not newly published ones, were installed during development and deployment.

Ibanez emphasized several practices to mitigate risks, such as always committing the “lockfile” to version control, using Performant NPM (PNPM) when possible, and avoiding the use of the caret (^) symbol in package.json to prevent unintended version upgrades.

The software developer kit maintained by Ripple and distributed through NPM receives over 140,000 downloads per week, with developers widely using it to build applications on the XRP Ledger. 

The XRP Ledger Foundation removed the affected versions from the NPM registry shortly after the disclosure. Still, it remains unknown how many users had integrated the compromised versions before the issue was flagged.

See also  Telegram Game on Brand-New Ethereum Layer-2 Scaler Blast Exploited for $4,600,000 in Reported White Hat Hack
Mentioned in this article

Source link

Backdoor Compromised developer keys kit Ledger Private Steal wallet XRP
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

XRP retail returns as whale gap hits 2024 low of 89.3% – Details

May 2, 2026

New Partnership Aims to Redefine Private Crypto Transactions Across 200+ Chains

May 2, 2026

Digital Asset Security Moves Beyond Keys as Bitgo Adds 5-Layer Checks

May 1, 2026

EMURGO Expands Cardano Ecosystem by Acquiring Ctrl Wallet, ADA Rises

May 1, 2026
View 3 Comments

3 Comments

  1. Effie2345 on April 23, 2025 1:39 am

    Very good https://is.gd/tpjNyL

    Reply
  2. Travis192 on April 23, 2025 3:01 am

    Very good https://is.gd/tpjNyL

    Reply
  3. Monty Acheson on May 2, 2025 10:21 pm

    I conceive this internet site contains very excellent composed subject matter content.

    Reply
Leave A Reply Cancel Reply

Top Posts

Bitcoin miners Hut 8, USBTC prepares for halving with merger into new company

December 1, 2023

What are dynamic NFTs? | NFT News Today

October 16, 2025

Ethereum steals the show in record $11.2B July inflows

July 31, 2025

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Bitcoin above $78K, ETH, SOL, DOGE higher as Senate clears Clarity Act yield hurdle

May 2, 2026

Ex SEC advisor joins KAST as stablecoin policy race heats up

May 2, 2026

The GENIUS Act opened the door for stablecoins, but regulators want to narrow it

May 2, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$78,207.001.13%
  • ethereumEthereum(ETH)$2,304.220.89%
  • tetherTether(USDT)$1.000.02%
  • rippleXRP(XRP)$1.390.82%
  • binancecoinBNB(BNB)$615.28-0.45%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$83.76-0.29%
  • tronTRON(TRX)$0.3303491.43%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.030.14%
  • dogecoinDogecoin(DOGE)$0.107779-1.04%