Executive brief
The official JavaScript library for interacting with the XRP Ledger was compromised in a supply chain attack. Malicious code was inserted into specific versions of the library to steal private cryptographic keys from users and applications. This could lead to the total loss of digital assets and unauthorized control over XRP Ledger accounts.
Technical details
This is a supply chain compromise affecting the xrpl.js npm package (CWE-506). Malicious code was embedded in versions 4.2.1 through 4.2.4, as well as version 2.14.2, specifically designed to exfiltrate private keys to an attacker-controlled server. The attack requires no authentication or user interaction beyond the use of the compromised library in a Node.js or browser environment. Successful exploitation allows an attacker to gain full control over the victim's XRP Ledger accounts. Users must upgrade to version 4.2.5 or 2.14.3 and are strongly advised to rotate any keys exposed while using the affected versions.
Affected products
- XRPLF xrpl.js 4.2.1, 4.2.2, 4.2.3, 4.2.4, 2.14.2
Timeline
- 2025-04-22: disclosed
- 2025-04-22: advisory
- 2025-04-22: patched: Versions 4.2.5 and 2.14.3 released
References
- https://github.com/XRPLF/xrpl.js/security/advisories/GHSA-33qr-m49q-rxfx
- https://github.com/XRPLF/xrpl.js
- https://www.aikido.dev/blog/xrp-supplychain-attack-official-npm-package-infected-with-crypto-stealing-backdoor
- https://xrpl.org/docs/tutorials/how-tos/manage-account-settings/assign-a-regular-key-pair
- https://xrpl.org/docs/tutorials/how-tos/manage-account-settings/disable-master-key-pair