Today’s Ripple Updates: XRPL Library Vulnerability Resolved Following Major Issue
A threat actor seemingly exploited an XRP Ledger’s developer access token to publish illicit code to the burgeoning network in a move that could have been “catastrophic” for the network, according to the security team that identified the issue. Charlie Eriksen, a researcher at Aikido Security who first spotted the problem, stated that a hidden issue was incorporated into recent versions of a new toolkit used to develop applications for the XRP Ledger. “A developer’s NPM access token was stolen by the threat actors,” Aikido reported on X. “It is unclear how this occurred, and the identities of the threat actors remain uncertain (though we have a theory we are working to confirm).” This issue affects only versions of Node Package Manager (NPM), a platform where developers share reusable code for various projects. Major XRP-related services, such as Xaman Wallet and XRPScan, confirmed they were not affected in separate communications on X. This flaw could potentially allow attackers to steal users’ private keys, giving them access to users’ crypto wallets in theory.
“At 21 Apr, 20:53 GMT+0, our system, Aikido Intel, started to alert us to five new package versions of the xrpl package. It is the official SDK for the XRP Ledger, boasting more than 140,000 weekly downloads,” Eriksen mentioned in a security update. “This package is utilized by hundreds of thousands of applications and websites, making it a potentially catastrophic supply chain attack on the cryptocurrency ecosystem,” Eriksen added. He emphasized that only third-party applications or services that installed the flawed versions during a brief period could be at risk.
In response, the XRP Ledger Foundation team promptly addressed the issue by releasing updated versions of the tool to replace the compromised ones. The affected versions (v4.2.1-4.2.4 and v2.14.2) were deprecated. “To clarify: This vulnerability is in xrpl.js, a JavaScript library for interacting with the XRP Ledger. It does NOT affect the XRP Ledger codebase or GitHub repository itself. Projects using xrpl.js should upgrade to v4.2.5 immediately,” the foundation posted separately. A JavaScript library is a collection of pre-written code that simplifies tasks in web development. A GitHub repository is an online storage space for a project’s code, files, and history, hosted on GitHub. XRP prices have risen 8.5% over the past 24 hours, reflecting a broader market uptick.
