Close Menu
    Crypto News Flash
    • News
      • Bitcoin News
      • Ripple (XRP) News
      • Success Stories
      • Shiba Inu News
      • Dogecoin News
      • Cardano News
      • VeChain News
      • IOTA News
    • Marketcap
    • Buy Crypto
      • Buy Bitcoin
      • Buy Litecoin
      • See all guides
    • Wallets
      • Bitcoin Wallet
      • Ethereum Wallet
      • Dogecoin Wallet
      • Aptos wallet
      • See all guides
    • Advertise
    • Crypto News Flash is Hiring!
    • English
    Crypto News Flash
    You are at:Startseite » XRP Ledger Foundation Flags JavaScript Security Risk—Update Required
    News

    XRP Ledger Foundation Flags JavaScript Security Risk—Update Required

    James M. GathechaBy James M. Gathecha23. April 20250
    John Kiguru By John Kiguru 23. April 2025 Updated: 23. April 2025
    3 Mins Read
    XRPL XRP Ledger
    • Blockchain security researcher from Alkido identified a serious vulnerability in the xrpl npm package v4.2.1-4.2.4 and v2.14.2.
    • This package is used by hundreds of thousands of applications and websites that steal private keys as soon as a Wallet object is instantiated.

    On April 22, the XRP Ledger Foundation issued an urgent security warning regarding a critical vulnerability in its official JavaScript library, xrpl.js, that developers use to interact with the XRP Ledger blockchain. The vulnerability was identified as a sophisticated supply chain attack, in which malware code was inserted in some versions of the xrpl.js package that can undermine the security of cryptocurrency wallets utilizing this library.​ Aikido Intel, Aikido’s public threat feed that uses LLMs to monitor the public package managers, discovered the vulnerability.

    The affected versions of xrpl.js, specifically v4.2.1 through v4.2.4 and v2.14.2, contained a backdoor function named checkValidityOfSeed. The function was designed to pilfer private keys by sending them to an external unauthorized domain when generating or operating with a wallet.

    The malware was inserted by an individual using the NPM account “mukulljangid,” which published these tainted versions to the Node Package Manager (NPM) registry. An NPM package is a reusable module for Node.js and JavaScript applications that simplifies installation, updates, and uninstallation. These versions were not in sync with any release on the XRP Ledger Foundation’s GitHub repository, which immediately aroused suspicions among security researchers.

    Impact Evaluation

    The bug revealed a critical vulnerability to any application or service utilizing the compromised versions of xrpl.js because it could lead to unauthorized access to users’ private keys and subsequent loss of funds. Notably, the XRP Ledger blockchain and official GitHub repository were not impacted.

    Other XRP-related projects, such as Xamans Wallet, XRPScan, First Ledger, and Gen3 Games, announced that they were not impacted by the breach, either by publishing safe versions of the library or utilizing other infrastructure. 

    As a result of this, the XRP Ledger Foundation simultaneously deprecated all of the compromised versions of xrpl.js on NPM to avoid future downloads. The vulnerable versions of xrpl.js on NPM should be updated right away to prevent additional downloads. It released a patched version, v4.2.5, which eliminates the malicious code and restores secure functionality.

    Developers and projects using the vulnerable versions of the xrpl.js library are advised to take immediate action to secure their systems and user funds. They are recommended to upgrade to the fixed release, xrpl.js v4.2.5, or downgrade to the stable and unaffected v2.14.3. Additionally, any exposed secrets or private keys are to be rotated right away. As an additional precaution, vulnerable master keys are to be deactivated and replaced with newly generated standard key pairs to ensure security and integrity.

    With this in mind, XRP has broken through the key resistance level of $2.20, rising to $2.26 after a 7.71% increase in the last 24 hours. This price surge has been mirrored by an increase in trading, with daily volume increasing by 104.04% to $5.04 billion.


    Recommended for you:
    • Buy Ripple (XRP) Guide
    • Ripple XRP Wallet Tutorial
    • Check 24-hour XRP Price
    • More Ripple (XRP) News
    • What is Ripple (XRP)?
    XRP XRP Ledger XRPL
    This article is provided for informational purposes only and is not intended as investment advice. The content does not constitute a recommendation to buy, sell, or hold any securities or financial instruments. Readers should conduct their own research and consult with financial advisors before making investment decisions. The information presented may not be current and could become outdated.
    Previous ArticleCrypto News: ADA and ETH Rally While BTC Decouples—Altcoin Season Incoming?
    Next Article Dogecoin Price Slides While a ‘Forgotten’ Altcoin Begins Climbing the Charts
    James M. Gathecha
    • Website
    • X (Twitter)

    James is dedicated to demystifying intricate technological concepts. His keen eye for details has positioned him as a trusted voice in decentralized technologies. With years of experience, she creates insightful articles, in-depth analyses, and captivating narratives that uncover the potential and hurdles within the crypto and blockchain landscape. Business Email: [email protected] Phone: +49 160 92211628

    Related Posts

    The Untold Story Behind Ameer Rosic and Blockgeeks

    Stellar Wallet Moves Raise Eyebrows—Is Pi Network Headed to Binance?

    Donald Trump Quietly Accumulated Bitcoin, Eric Trump Confirms

    The Untold Story Behind Ameer Rosic and Blockgeeks
    8. May 2025
    Stellar Wallet Moves Raise Eyebrows—Is Pi Network Headed to Binance?
    8. May 2025
    Donald Trump Quietly Accumulated Bitcoin, Eric Trump Confirms
    8. May 2025
    Analyst Sees 300% Rally Potential for Litecoin This Cycle
    8. May 2025
    ABOUT US AND ADDITIONAL INFO
    Crypto News FlashCrypto News Flash is your number one source for the latest news and information from the world of cryptocurrencies.

    About us
    Contact us
    Editorial Guidelines
    Terms of Use
    Legals
    Data protection policy
    Cookie Policy

    *= Affiliate-Link

    Charts
    • Bitcoin Price
    • Ethereum Price
    • XRP Price
    • Litecoin Price
    • Bitcoin Cash Price
    • EOS Price
    • Cardano Price
    • Tron Price
    • IOTA Price
    • Monero Price
    Buy Cryptocurrencies
    • Buy Bitcoin
    • Buy Ethereum
    • Buy XRP
    • Buy Litecoin
    • Buy Bitcoin Cash
    • Buy EOS
    • Buy Cardano
    • Buy Tron
    • Buy IOTA
    • Buy Monero
    Wallets
    • Bitcoin Wallet
    • Ethereum Wallet
    • XRP Wallet
    • Litecoin Wallet
    • Bitcoin Cash Wallet
    • EOS Wallet
    • Cardano Wallet
    • Tron Wallet
    • IOTA Wallet
    • Monero Wallet
    Risk warning and disclaimer: The contents of this website are intended solely for the entertainment and information of readers and do not provide investment advice or a recommendation within the context of the Securities Trading Act. The content of this website solely reflects the subjective and personal opinion of the authors. Readers are requested to form their own opinions on the contents of this website and to seek professional and independent advice before making concrete investment decisions. The information found on this site does not contain any information or messages, but is intended solely for information and personal use. None of the information shown constitutes an offer to buy or sell futures contracts, securities, options, CFDs, other derivatives or cryptocurrencies. Any opinions provided, including e-mails, live chat, SMS or other forms of communication across social media networks do not constitute a suitable basis for an investment decision. You alone bear the risk for your investment decisions.

    Type above and press Enter to search. Press Esc to cancel.