logo

Supply Chain Attack on lottie-player (Campaign)

ID: 944cf9e5-6c64-580a-ab8c-d8db4b075d7b

STIX ID: report--944cf9e5-6c64-580a-ab8c-d8db4b075d7b

Feed Name: Wiz Cloud Threat Landscape

Threat Score
85/100

Date Published: 2024-10-31

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

On October 30, 2024, attackers gained access to a maintainer token for the lottie-player JavaScript library and pushed malicious versions (2.0.5–2.0.7) that injected Web3 wallet connection prompts into legitimate websites. The compromised packages were distributed via npm and major CDNs, leading to active impact (notably 1inch dApp users), after which affected versions were removed and a safe release (2.0.8) was published; sites explicitly referencing the malicious versions remain at risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.