A backdoor for stealing cryptocurrency has been discovered in the official XRP Ledger NPM package
Contents
Market Musing-g
A backdoor for stealing cryptocurrency has been discovered in the official XRP Ledger NPM package
XRP
XRP
Coin
CIN
Coin Edition Russia
Coin Edition Russia
4 days ago
•
1 min read
A backdoor for stealing cryptocurrency has been discovered in the official XRP Ledger NPM package
Contents
How malicious code affected NPM
A backdoor for stealing cryptocurrency was implanted in the official NPM XRP Ledger package.
Affected NPM versions — 4.2.1–4.2.4 and 2.14.2.
Users need to upgrade to patched versions and rotate private keys.
A supply chain attack compromised the official XRP Ledger JavaScript SDK by injecting a backdoor into certain NPM versions. The backdoor in certain NPM versions targeted the theft of private keys, putting connected XRP wallets at risk.
SlowMist released a high-priority alert calling for immediate updates and credential rotation.
How malicious code affected NPM
The attack was focused around the xrpl NPM package