xrpl-ts@1.0.2
Malicious code in xrpl-ts (npm)
Analysis
xrpl-ts is a combosquat of the legitimate xrpl XRP Ledger library. It bundles a trojanized copy of the real library where Wallet.fromSeed() has been modified to exfiltrate wallet seeds to a Telegram bot. When any wallet is derived via Wallet.generate(), Wallet.fromSeed(), Wallet.fromSecret(), Wallet.fromMnemonic(), or Wallet.fromEntropy(), the seed (private key material) is POSTed to api[.]telegram[.]org via a hardcoded bot token and chat ID in the request URL. The exfiltration code is injected into packages/xrpl/src/Wallet/index.ts and runs whenever the library creates or restores a wallet. IOCs: Telegram C2 at api[.]telegram[.]org; a hardcoded bot token and chat ID in the Wallet.fromSeed() method.
- analyzed by
- Leitwacht
- first seen
- Jun 16, 2026, 07:51 AM
- analyzed
- Jun 16, 2026, 07:52 AM
Related advisories
- xmr-btc-lib-js@1.2.1
- xeiko-cdn@1.0.0
- xboxauthwrapper@3.9.8
- chai-solidity-testkit@1.6.1
- workbox-stable-xyz@1.0.0
- wordsmith-kit@1.0.0
- wisdomtreetest@1.0.1
- winston-prism@1.0.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.