Junglewise Threat Intelligence

CVE-2025-32965: XRPLF xrpl.js embedded malicious code in supply chain attack

CVE-2025-32965 · Severity: medium · CVSS 4 · Published 2025-04-22

Executive brief

The official JavaScript library for interacting with the XRP Ledger was compromised in a supply chain attack. Malicious code was inserted into specific versions of the library to steal private cryptographic keys from users and applications. This could lead to the total loss of digital assets and unauthorized control over XRP Ledger accounts.

Technical details

This is a supply chain compromise affecting the xrpl.js npm package (CWE-506). Malicious code was embedded in versions 4.2.1 through 4.2.4, as well as version 2.14.2, specifically designed to exfiltrate private keys to an attacker-controlled server. The attack requires no authentication or user interaction beyond the use of the compromised library in a Node.js or browser environment. Successful exploitation allows an attacker to gain full control over the victim's XRP Ledger accounts. Users must upgrade to version 4.2.5 or 2.14.3 and are strongly advised to rotate any keys exposed while using the affected versions.

Affected products

  • XRPLF xrpl.js 4.2.1, 4.2.2, 4.2.3, 4.2.4, 2.14.2

Timeline

  • 2025-04-22: disclosed
  • 2025-04-22: advisory
  • 2025-04-22: patched: Versions 4.2.5 and 2.14.3 released

References