Security
Headlines
HeadlinesLatestCVEs

Headline

Ripple's xrpl.js npm Package Backdoored to Steal Private Keys in Major Supply Chain Attack

The Ripple cryptocurrency npm JavaScript library named xrpl.js has been compromised by unknown threat actors as part of a software supply chain attack designed to harvest and exfiltrate users’ private keys. The malicious activity has been found to affect five different versions of the package: 4.2.1, 4.2.2, 4.2.3, 4.2.4, and 2.14.2. The issue has been addressed in versions 4.2.5 and 2.14.3.

The Hacker News
#nodejs#js#java#backdoor#The Hacker News

The Hacker News: Latest News

NightEagle APT Exploits Microsoft Exchange Flaw to Target China's Military and Tech Sectors