Wednesday, 21 May 2025
  • My Feed
  • My Interests
  • My Saves
  • History
  • Blog
Subscribe
Capernaum
  • Finance
    • Cryptocurrency
    • Stock Market
    • Real Estate
  • Lifestyle
    • Travel
    • Fashion
    • Cook
  • Technology
    • AI
    • Data Science
    • Machine Learning
  • Health
    HealthShow More
    Eating to Treat Crohn’s Disease 
    Eating to Treat Crohn’s Disease 

    Switching to a plant-based diet has been shown to achieve far better…

    By capernaum
    Eating to Keep Ulcerative Colitis in Remission 
    Eating to Keep Ulcerative Colitis in Remission 

    Plant-based diets can be 98 percent effective in keeping ulcerative colitis patients…

    By capernaum
    Foods That Disrupt Our Microbiome
    Foods That Disrupt Our Microbiome

    Eating a diet filled with animal products can disrupt our microbiome faster…

    By capernaum
    Skincare as You Age Infographic
    Skincare as You Age Infographic

    When I dove into the scientific research for my book How Not…

    By capernaum
    Treating Fatty Liver Disease with Diet 
    Treating Fatty Liver Disease with Diet 

    What are the three sources of liver fat in fatty liver disease,…

    By capernaum
  • Sport
  • 🔥
  • Cryptocurrency
  • Travel
  • Data Science
  • Real Estate
  • AI
  • Technology
  • Machine Learning
  • Stock Market
  • Finance
  • Fashion
Font ResizerAa
CapernaumCapernaum
  • My Saves
  • My Interests
  • My Feed
  • History
  • Travel
  • Health
  • Technology
Search
  • Pages
    • Home
    • Blog Index
    • Contact Us
    • Search Page
    • 404 Page
  • Personalized
    • My Feed
    • My Saves
    • My Interests
    • History
  • Categories
    • Technology
    • Travel
    • Health
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Home » Blog » XRP Ledger Foundation Flags JavaScript Security Risk—Update Required
Cryptocurrency

XRP Ledger Foundation Flags JavaScript Security Risk—Update Required

capernaum
Last updated: 2025-04-23 17:06
capernaum
Share
XRP Ledger Foundation Flags JavaScript Security Risk—Update Required
SHARE

XRPL XRP Ledger

  • Blockchain security researcher from Alkido identified a serious vulnerability in the xrpl npm package v4.2.1-4.2.4 and v2.14.2.
  • This package is used by hundreds of thousands of applications and websites that steal private keys as soon as a Wallet object is instantiated.

On April 22, the XRP Ledger Foundation issued an urgent security warning regarding a critical vulnerability in its official JavaScript library, xrpl.js, that developers use to interact with the XRP Ledger blockchain. The vulnerability was identified as a sophisticated supply chain attack, in which malware code was inserted in some versions of the xrpl.js package that can undermine the security of cryptocurrency wallets utilizing this library.​ Aikido Intel, Aikido’s public threat feed that uses LLMs to monitor the public package managers, discovered the vulnerability.

The affected versions of xrpl.js, specifically v4.2.1 through v4.2.4 and v2.14.2, contained a backdoor function named checkValidityOfSeed. The function was designed to pilfer private keys by sending them to an external unauthorized domain when generating or operating with a wallet.

The malware was inserted by an individual using the NPM account “mukulljangid,” which published these tainted versions to the Node Package Manager (NPM) registry. An NPM package is a reusable module for Node.js and JavaScript applications that simplifies installation, updates, and uninstallation. These versions were not in sync with any release on the XRP Ledger Foundation’s GitHub repository, which immediately aroused suspicions among security researchers.

Impact Evaluation

The bug revealed a critical vulnerability to any application or service utilizing the compromised versions of xrpl.js because it could lead to unauthorized access to users’ private keys and subsequent loss of funds. Notably, the XRP Ledger blockchain and official GitHub repository were not impacted.

Other XRP-related projects, such as Xamans Wallet, XRPScan, First Ledger, and Gen3 Games, announced that they were not impacted by the breach, either by publishing safe versions of the library or utilizing other infrastructure. 

As a result of this, the XRP Ledger Foundation simultaneously deprecated all of the compromised versions of xrpl.js on NPM to avoid future downloads. The vulnerable versions of xrpl.js on NPM should be updated right away to prevent additional downloads. It released a patched version, v4.2.5, which eliminates the malicious code and restores secure functionality.

Developers and projects using the vulnerable versions of the xrpl.js library are advised to take immediate action to secure their systems and user funds. They are recommended to upgrade to the fixed release, xrpl.js v4.2.5, or downgrade to the stable and unaffected v2.14.3. Additionally, any exposed secrets or private keys are to be rotated right away. As an additional precaution, vulnerable master keys are to be deactivated and replaced with newly generated standard key pairs to ensure security and integrity.

With this in mind, XRP has broken through the key resistance level of $2.20, rising to $2.26 after a 7.71% increase in the last 24 hours. This price surge has been mirrored by an increase in trading, with daily volume increasing by 104.04% to $5.04 billion.

Share This Article
Twitter Email Copy Link Print
Previous Article Here’s Why Pi Network Price Will Remain Capped Because These 3 Exchanges Will Not List Pi Coin Here’s Why Pi Network Price Will Remain Capped Because These 3 Exchanges Will Not List Pi Coin
Next Article Anne Hathaway Attended the Ralph Lauren FW ’25 Show in a Khaki Trench Coat and Sequined Jeans Anne Hathaway Attended the Ralph Lauren FW ’25 Show in a Khaki Trench Coat and Sequined Jeans
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Using RSS feeds, we aggregate news from trusted sources to ensure real-time updates on the latest events and trends. Stay ahead with timely, curated information designed to keep you informed and engaged.
TwitterFollow
TelegramFollow
LinkedInFollow
- Advertisement -
Ad imageAd image

You Might Also Like

Will Altcoins Explode in June 2025 After FTX’s $5 Billion Distribution?
Cryptocurrency

Will Altcoins Explode in June 2025 After FTX’s $5 Billion Distribution?

By capernaum
Standard Chartered Predicts $500K Bitcoin as Faith in Government Bonds Fades
Cryptocurrency

Standard Chartered Predicts $500K Bitcoin as Faith in Government Bonds Fades

By capernaum

BTC Price is Less Than 2% Away for ATH, Is a $110K Possible Today?

By capernaum

Hong Kong Takes Lead in Crypto Regulation with Stablecoin Bill as US Trails Behind

By capernaum
Capernaum
Facebook Twitter Youtube Rss Medium

Capernaum :  Your instant connection to breaking news & stories . Stay informed with real-time coverage across  AI ,Data Science , Finance, Fashion , Travel, Health. Your trusted source for 24/7 insights and updates.

© Capernaum 2024. All Rights Reserved.

CapernaumCapernaum
Welcome Back!

Sign in to your account

Lost your password?