Snyk has reported that there have been attempts or successful attacks targeting this vulnerability.
The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsAvoid using all malicious instances of the xrpl
package.
xrpl is an A TypeScript/JavaScript API for interacting with the XRP Ledger in Node.js and the browser
Affected versions of this package are vulnerable to Embedded Malicious Code that steals cryptocurrency private keys and can provide access to cryptocurrency wallets. A malicious actor published multiple malicious versions of the xrpl
package, which contain a payload intended to steal private keys upon the instantiation of a Wallet object.
Notes: