A blockchain security expert from Alkido has discovered a significant flaw in the xrpl npm package version 22.20.22.26-2.26. 224 and v2104.04. On April 25, it was noted that hundreds of thousands of applications and websites exploit this package to steal private keys immediately upon the creation of a Wallet object. The XRP Ledger Foundation released an urgent security alert on April 22, highlighting a significant vulnerability in its official JavaScript library, xrpl. JavaScript utilized by developers to engage with the XRP Ledger blockchain. The vulnerability was recognized as a complex supply chain attack, where malicious code was embedded in certain versions of the xrpl. JavaScript library that could compromise the security of cryptocurrency wallets by using this package. Aikido Intel, which operates Aikido’s public threat feed utilizing LLMs to keep an eye on public package managers, identified the vulnerability. This issue pertains to specific versions of xrpl. JavaScript, particularly version 4.2.
Related Posts

Crypto On The Rise: TON Blockchain And Mocaverse Join Forces To Drive Adoption. Here’s Why You Should Care
In a move that could reshape the blockchain landscape, TON Blockchain has partnered with Animoca Brands’ Mocaverse and the MOCA…

How is Terra Luna Classic’s Staking Surge Impacting Tokenomics?
In a significant development for the Terra Luna Classic (LUNC) community, the staking ratio has reached a new high with…
Bitcoin’s strong market presence may propel MAGACOIN FINANCE, XRP, and Cardano towards the potential for a 1,000x increase.
With the crypto market moving forward into mid-2025, there is increasing interest in a specific set of assets that demonstrate…