Ripple NPM supply chain attack hunts for private keys
- Threat actors compromised the xrpl.js JavaScript library for interacting with the XRP Ledger.
- Attackers used a compromised developer NPM account in a software supply chain attack.
- They injected malicious code starting April 21, 2025 to steal user private keys.
- Modified versions accumulated 452 downloads before removal from NPM.
- Users should upgrade immediately to versions 4.2.5 or 2.14.3.
18 Articles
18 Articles
Ripple Developer Tools Hacked: What Went Wrong and What’s Next
XRP recently faced a serious security incident when a malicious actor compromised one of its core development tools, the JavaScript library xrpl.js. This software supply chain attack affected specific versions of the library published on the Node Package Manager (NPM), putting users’ private keys at risk. Aikido Security initially flagged the issue, and Ripple’s Chief Technology Officer, David Schwartz, later confirmed the breach. The attack com…
Crypto-Stealing Backdoor Found in Official XRP Ledger NPM Package
XRP Ledger’s official NPM package was injected with a crypto-stealing backdoor. The affected NPM versions are 4.2.1 to 4.2.4 and 2.14.2. Users must upgrade to patched versions and rotate private keys. A supply chain attack compromised the official XRP Ledger JavaScript SDK, injecting a backdoor into specific versions of NPM. A backdoor in specific NPM versions targeted private key theft, putting connected XRP wallets at risk. SlowMist issued a …
Coverage Details
Bias Distribution
- 100% of the sources are Center
To view factuality data please Upgrade to Premium
Ownership
To view ownership data please Upgrade to Vantage