XRP Ledger Bugs are patched after ‘Severe’ error stained in the XRPL Library

A threat actor who apparently exploited an XRP Ledger’s developer access token to publish illegal code to the budding network in a move that could have been “disastrous” for the network, the security team discovered the problem in an update.

Charlie Eriksen, a researcher at Aikido Security, who first discovered the problem, said a hidden problem was added to recent versions of a new tool set used to build apps that work with the XRP headbook.

“A developer’s NPM access token was stolen by the threat actors,” Aikido said at X. “It’s unclear where right now. It’s also unclear who threat actors are right now (even though we have a lunch we’re trying to confirm).”

The problem only affects versions of the Node Package Manager (NPM), a site where developers share recyclable code for projects. Major XRP-related services, such as Xaman Wallet and XRPSCAN, said they were not affected by separate X-positions.

This error could let attackers steal users’ private keys and possibly access to their crypto -draw books in theory.

“April 21, 20:53 GMT+0, Our System, Aikido Intel began to warn us of five new package versions of the XRPL package. That’s the official SDK for the XRP head box with more than 140,000 weekly downloads,” Eriksen said in a security update.

“This package is used by hundreds of thousands of applications and sites, making it a potentially disastrous supply chain attack on the cryptocurrency,” Eriksen noted.

He added that only third -party apps or services that installed the defective versions for a short period could be at risk.

As such, the XRP Ledger Foundation team quickly solved the problem by releasing updated versions of the tool to replace the defective. The affected versions (V4.2.1-4.2.4 and V2.14.2) were printed.

“To clarify: This vulnerability is in XRPL.JS, a JavaScript -Library for interaction with the XRP headbook. It does not affect the XRP Headbox Code or GitHub -Depot.

A JavaScript library is a collection of pre-written code to simplify tasks in web development. A GitHub -Repo is an online storage space for a project code, files and history that hosts GitHub.

The XRP prices have risen 8.5% over the past 24 hours next to a wider market jump.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top