logo

Lottie File Incidents: Case Studies of Third-Party Supply Chain Risks

ID: c423566b-6c74-571c-b4d2-59654281e241

STIX ID: report--c423566b-6c74-571c-b4d2-59654281e241

Feed Name: CertiK Blog

Threat Score
80/100

Date Published: 2025-08-10

Date Updated: 2026-06-11

...
...

This report details two Lottie-related security incidents: (1) an XSS exploit abusing lottie-web's expression evaluation that was used to show fake "Verify Wallet" pop-ups on CoinMarketCap via a malicious doodle, and (2) a supply-chain compromise of the @lottiefiles/lottie-player npm package where attacker-published versions prompted users to connect wallets. The document provides attack paths, PoC artifacts, detection steps, and recommended mitigations such as disabling expressions, enforcing CSP, pinning dependencies, and using SRI.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.