Ripple XPRL Official NPM Package Hijacked To Inject Private Key Stealing Malware

A significant supply chain attack targeting cryptocurrency users. The official XRPL (Ripple) NPM package, which serves as the JavaScript SDK for the XRP Ledger, was compromised with malicious code designed to steal cryptocurrency private keys, potentially affecting hundreds of thousands of applications. On April 21, 2025, at 20:53 GMT, Aikido Intel’s security monitoring system detected […]

The post Ripple XPRL Official NPM Package Hijacked To Inject Private Key Stealing Malware appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: