Malware Steals Private Keys from XRPL Code, Threatening $80 Million in DeFi

A malicious npm package has compromised the XRP Ledger SDK, potentially exposing users’ private keys and jeopardizing up to $80 million in DeFi assets. The breach stems from a backdoor embedded by an attacker who targeted five versions of the software. This incident highlights the vulnerability of open-source projects and urges developers to update their dependencies immediately. While no confirmed thefts have been reported, experts emphasize the need for vigilance against supply chain attacks in the face of these risks.