A backdoor for stealing cryptocurrency has been discovered in the official XRP Ledger NPM package

Contents

Market Musing-g

A backdoor for stealing cryptocurrency has been discovered in the official XRP Ledger NPM package

XRP

XRP

Coin

CIN

Coin Edition Russia

Coin Edition Russia

4 days ago

1 min read

A backdoor for stealing cryptocurrency has been discovered in the official XRP Ledger NPM package

Contents

How malicious code affected NPM

A backdoor for stealing cryptocurrency was implanted in the official NPM XRP Ledger package.

Affected NPM versions — 4.2.1–4.2.4 and 2.14.2.

Users need to upgrade to patched versions and rotate private keys.

A supply chain attack compromised the official XRP Ledger JavaScript SDK by injecting a backdoor into certain NPM versions. The backdoor in certain NPM versions targeted the theft of private keys, putting connected XRP wallets at risk.

SlowMist released a high-priority alert calling for immediate updates and credential rotation.

How malicious code affected NPM

The attack was focused around the xrpl NPM package