All Things XRP (@XRP_investing), a widely known XRP enthusiast, alerted XRP holders about a major security breach affecting the XRP Ledger JavaScript SDK. His post warned users that a hacker had placed a backdoor in several recent versions of the XRPL package on NPM, a package manager used by countless cryptocurrency developers.

The compromised versions, 4.2.1 to 4.2.4 and 2.14.2, may steal users' private keys. This exploit was initially discovered by Aikido Security. The hacker infiltrated the official package and uploaded modified versions to NPM on April 21.