XRP Ledger SDK Compromised by Backdoor Exploit

XRP Ledger SDK Compromised by Backdoor Exploit

The XRP Ledger Foundation has warned about a security vulnerability in the official JavaScript SDK, which interacts with the XRPL.
On April 21, Aikido Security revealed that several versions of its Node Package Manager (NPM) software were compromised and published, containing a backdoor that could steal private keys from users.
Security Flaw in Developer Kit
The XRP Ledger Foundation confirmed the issue in an April 22 statement:

“Earlier today, a security researcher from @AikidoSecurity identified a serious vulnerability in the xrpl npm package (v4.2.1-4.2.4 and v2.14.2).”

In response to the breach, Wietse Wind, founder and CEO of XRPL Labs, reassured users that Xaman Wallet was not affected by the flaw. Wind explained that the product does not use xrpl.js but instead relies on its xrpl-client and xrpl-accountlib libraries, which separate wallet connectivity from the signing process.
He also detailed how the incident unfolded, stating that malicious code in the xrpl.js package se

Czytaj więcej

We współpracy z: https://cryptopotato.com/xrp-ledger-sdk-compromised-by-backdoor-exploit/

Total
0
Shares
Dodaj komentarz

Podobne Wpisy