web analytics

Ripple’s xrpl.js npm Package Backdoored to Steal Private Keys in Major Supply Chain Attack – Source:thehackernews.com

Rate this post

Source: thehackernews.com – Author: .

The Ripple cryptocurrency npm JavaScript library named xrpl.js has been compromised by unknown threat actors as part of a software supply chain attack designed to harvest and exfiltrate users’ private keys.
The malicious activity has been found to affect five different versions of the package: 4.2.1, 4.2.2, 4.2.3, 4.2.4, and 2.14.2. The issue has been addressed in versions 4.2.5 and 2.14.3.

Original Post url: https://thehackernews.com/2025/04/ripples-xrpljs-npm-package-backdoored.html

Category & Tags: –

Views: 2

LinkedIn
Twitter
Facebook
WhatsApp
Email

advisor pick´S post