Vulnerabilities/

Compromised xrpl.js versions 4.2.1, 4.2.2, 4.2.3, 4.2.4, and 2.14.2

Severity:
High

Description

Versions 4.2.1, 4.2.2, 4.2.3, and 4.2.4 of xrpl.js were compromised and contained malicious code designed to exfiltrate private keys. If you are using one of these versions, stop immediately and rotate any private keys or secrets used with affected systems.

Version 2.14.

Recommendation

Update the xrpl package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
xrpl
Anything's wrong? Let us know Last updated on April 22, 2025

This issue is available in SmartScanner Professional

See Pricing