Lottie File Incidents: Case Studies of Third-Party Supply Chain Risks
ID: c423566b-6c74-571c-b4d2-59654281e241
STIX ID: report--c423566b-6c74-571c-b4d2-59654281e241
Feed Name: CertiK Blog
This report details two Lottie-related security incidents: (1) an XSS exploit abusing lottie-web's expression evaluation that was used to show fake "Verify Wallet" pop-ups on CoinMarketCap via a malicious doodle, and (2) a supply-chain compromise of the @lottiefiles/lottie-player npm package where attacker-published versions prompted users to connect wallets. The document provides attack paths, PoC artifacts, detection steps, and recommended mitigations such as disabling expressions, enforcing CSP, pinning dependencies, and using SRI.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
