クリプトドットイン

暗号に強い人材のためのオルタナティブ・リンクトイン

XRP Ledger SDK Compromised by Backdoor Exploit

The XRP Ledger Foundation has warned about a security vulnerability in the official JavaScript SDK, which interacts with the XRPL.

On April 21, Aikido Security revealed that several versions of its Node Package Manager (NPM) software were compromised and published, containing a backdoor that could steal private keys from users.

Security Flaw in Developer Kit

The XRP Ledger Foundation confirmed the issue in an April 22 statement:

“Earlier today, a security researcher from @AikidoSecurity identified a serious vulnerability in the xrpl npm package (v4.2.1-4.2.4 and v2.14.2).”

In response to the breach, Wietse Wind, founder and CEO of XRPL Labs, reassured users that Xaman Wallet was not affected by the flaw. Wind explained that the product does not use xrpl.js but instead relies on its xrpl-client and xrpl-accountlib libraries, which separate wallet connectivity from the signing process.

He also detailed how the incident unfolded, stating that malicious code in the xrpl.js package sent generated or imported private keys to an external server controlled by the attacker. This enabled hackers to collect key pairs, wait for the wallets to be funded, and then steal the assets.

Wind urged anyone who had recently created an XRP wallet using the API or related tools to assume it had been compromised and to transfer their funds immediately.

He emphasized that such attacks can happen to any software relying on third-party libraries, and that developers must take precautions. He also advised limiting publishing access, scanning code before release, avoiding auto-publishing pipelines, and not managing private keys directly unless fully prepared to handle the associated risks.

XRPL Issues Urgent Patch

Following the incident, the XRP Ledger Foundation has released a clean version of the NPM package, removing the malicious code and ensuring the SDK is safe for developers to use again.

Aikido Security discovered the vulnerability after its automated threat monitoring system flagged suspicious updates to the XRPL package on NPM. These updates, published by a user named “mukulljangid”, included five new versions that did not match any official releases on the XRP Ledger’s GitHub repository.

After investigating, Aikido found that the compromised versions contained a malicious function called checkValidityOfSeed, which sent private keys to the hacker’s server at 0x9c[.]xyz, when users created a wallet that could allow them to steal their crypto.

Early versions (v4.2.1 and v4.2.2) hid the backdoor in compiled JavaScript files, while later versions (v4.2.3 and v4.2.4) embedded the malicious code directly in TypeScript source files, making it harder to detect. The compromised packages also removed development tools like Prettier and build scripts from the package.json file, showing intentional manipulation.

The incident comes only weeks after Ripple announced a $1.25 billion acquisition of prime brokerage firm Hidden Road, a move experts believe will turn XRPL into a major conduit for institutional funds.

According to Ripple CEO Brad Garlinghouse, the network will be used for post-trade settlements on some transactions, potentially turning it into a corporate-scale clearing and credit platform.

ポスト XRP Ledger SDK Compromised by Backdoor Exploit に初登場した。 クリプトポテト.


コメント

コメントを残す

メールアドレスが公開されることはありません。 ※ が付いている欄は必須項目です

最新フィード

人気カテゴリー

ウェブサイトを検索

人気記事

タグ

#AlexeyPertsev (1) #Bidenクリプトバン (1) #Biden選挙 (1) #BinanceVsCoinbase (1) #ビットコイン (458) #BitcoinETF (3) #ビットコイン基礎知識 (1) #ビットコインの取り扱い (1) #Bビットコイン価格 (5) #BitcoinPriceLevel (1) #BitcoinPump (1) #BitcoinReserve (1) #ビットコイン・サージ (1) #Bitcoinトップ (1) #Bitfinex (1) #ビットワイズ (1) #BracebridgeCapital (1) #BRC20トークン (1) #BTC取得 (1) #Bullish予測 (1) #Bullishセンチメント (1) #中国鉱業 (1) #CPプレビュー (1) #CryptoAsset (2) #CryptoBattle (1) #CryptoBoom (1) #CryptoExpert (1) #CryptoInsights (1) #クリプトマニア (1) #CryptoMarket (4) #CryptoPrediction (1) #Crypto予測 (1) 1TP5トリプトレギュレーション (2) #CryptoTakeoff (1) #CryptoTiming (1) #CryptoTips (1) #CryptoTreasury (1) #CryptoUncertainty(暗号の不確実性 (1) #Dデリバティブジャンプ (1) #Dogecoin (74) #Dogecoinゲイン (1) #Dogecoinボリューム (1) #ダッチコート (2) #ECコマース (1) #ElSalvadorビットコイン (1) #Ethereum (74) #EthereumPain (1) #EthereumPrice (1) 1TP5専門家の意見 (1) #Fedレートカット (1) #FiatCurrency (1) #フィナンシャル・インパクト (1) #フィナンシャル・プライバシー (1) #Firmシャットダウン (1) #F凍結アカウント (1) 1TP5自己資金 (1) #InflationData (1) 1TP5投資 (1) 1TP5投資損失 (1) #日本ファーム (1) #法的措置 (1) 1TP5法的影響 (1) #法律 (1) #LightningNetwork (1) #市場分析 (3) #Mマーケットモニタリング (1) #M市場予測 (1) #市場予測 (1) #M市場予測 (1) #Mマーケットサポート (1) #マーケットボラティリティ (1) #マリッジ (1) #MemeCoin (5) #Memeコイン (2) #Miner収益性 (1) #マネーロンダリング (2) #MtGox (4) #北朝鮮暗号 (1) #ノボグラッツ予想 (1) #Priceマイルストーン (1) #P価格予測 (2) #Price質問 (1) #プライスサージ (1) #Prisonセンテンス (1) #QuantAnalysis (1) 1TP5規制圧力 (1) #SECアンチクリプト (1) #ShibaInu (6) #SocialBuzz (1) #技術分析 (1) #トンコイン (3) #トルネードキャッシュ (3) #TornadoCashDev (1) #TornadoCashデベロッパー (1) #UKクリプト (1) #Upsideポテンシャル (1) #USCongress(米国議会 (1) #ワイオミングランド (1) #XRP価格 (1) #XRPupswing (1)

お役立ちリンク

私が役に立ち、共有したいと思ったリンク