Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Massive Android fraud operations are detected: iconade, kaleidoscope, malicious SMS software, NFC scams

July 3, 2025

Chinese hackers operate Ivanti CSA Zero-Days in attacks on the French government, telecommunications

July 3, 2025

More than 40 malicious Firefox extensions target cryptocurrency wallets, steel assets

July 3, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Package NPM Ripple’s XRPL.JS RUSE
Global Security

Package NPM Ripple’s XRPL.JS RUSE

AdminBy AdminApril 23, 2025No Comments2 Mins Read
Ripple's xrpl.js npm Package Backdoored
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


April 23, 2025Red LakshmananBlockchain / cryptocurrency

Package NPM Ripple's XRPL.JS

Named Cryptocurrency Ripple XRPL.JS was compromised by unknown threats within the frame of supplying software designed to collect and private customer keys.

It was found that the harmful activity affected five different versions of the package: 4.2.1, 4.2.2, 4.2.3, 4.2.4 and 2.14.2. The question was address In versions 4.2.5 and 2.14.3.

Cybersecurity

XRPL.JS – Popular API JavaScript for interaction with XRP Ledger Blockchain, also called Ripple, is a cryptocurrency platform launched by Ripple laboratories in 2012. The package was downloaded To date, more than 2.9 million times, attracting more than 135,000 downloads of the weekly.

“The official NPM XPRL package was compromised by the complex attackers who put into the back of the theft of private cryptocurrency keys and access cryptocurrencies’ wallets,” Charlie Eriksen Aikido Security – Note.

The malicious code changes have been made by a user called “Mukulljangid“On April 21, 2025, when threatening subjects are a new feature called CheckValityofSeed, which is designed to transmit stolen information to an external domain (” 0x9c (.) XYZ “).

It is worth noting that “Mukulljangid” is likely belongs to Ripple employeeindicating that their NPM account was hacked to remove the supply chain attack.

It is said that the attacker tried different ways to get into the back corner, trying to avoid detecting, as evidenced by different versions released in a short period of time. There is no evidence that the related gitHub repository was back.

Cybersecurity

It is unclear who is behind the attack, but it is believed that the threat subjects managed to steal a marker of access to the developer to connect the library.

In the light of the incident, users who rely on the XRPL.JS library are recommended to update their instances to the latest version (4.2.5 and 2.14.3) to mitigate potential threats.

“This vulnerability is located in XRPL.JS, JavaScript Library for interaction with XRP Ledger”, the XRP Ledger Fund – Note In a message on X. “This does not affect the Codger XRP repositors or GitHub repositors. Projects using XRpl.js should immediately update to v4.2.5.

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Massive Android fraud operations are detected: iconade, kaleidoscope, malicious SMS software, NFC scams

July 3, 2025

Chinese hackers operate Ivanti CSA Zero-Days in attacks on the French government, telecommunications

July 3, 2025

More than 40 malicious Firefox extensions target cryptocurrency wallets, steel assets

July 3, 2025

CISCO’s critical vulnerability in uniform grants on root access to static credentials

July 3, 2025

North Korean Hackers Target Web3 with malicious NIM software and use Clickfix in Babyshark

July 2, 2025

Hackers using PDFs to get yourself for Microsoft, Docusign and more in phishing campaigns return call

July 2, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Massive Android fraud operations are detected: iconade, kaleidoscope, malicious SMS software, NFC scams

July 3, 2025

Chinese hackers operate Ivanti CSA Zero-Days in attacks on the French government, telecommunications

July 3, 2025

More than 40 malicious Firefox extensions target cryptocurrency wallets, steel assets

July 3, 2025

CISCO’s critical vulnerability in uniform grants on root access to static credentials

July 3, 2025

North Korean Hackers Target Web3 with malicious NIM software and use Clickfix in Babyshark

July 2, 2025

Hackers using PDFs to get yourself for Microsoft, Docusign and more in phishing campaigns return call

July 2, 2025

This network traffic looks legal but it can hide a serious threat

July 2, 2025

US Sanctions of Russia

July 2, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Massive Android fraud operations are detected: iconade, kaleidoscope, malicious SMS software, NFC scams

July 3, 2025

Chinese hackers operate Ivanti CSA Zero-Days in attacks on the French government, telecommunications

July 3, 2025

More than 40 malicious Firefox extensions target cryptocurrency wallets, steel assets

July 3, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.