"XRP Ledger Foundation Suffers Private Key Theft Attempt in Supply Chain Hack, Issues Emergency Fix":
‘“This package is used by hundreds of thousands of applications and websites making it a potentially catastrophic supply chain attack on the cryptocurrency ecosystem.”
It remains unclear how many users may have installed or integrated the backdoored versions before they were flagged. The episode serves as a stark reminder of the risks involved in software supply chains—where trust in a widely used development package can be exploited to infiltrate countless systems in a single, coordinated strike.