Differential analysis raises red flags over @lottiefiles/lottie-player
ID: 448b3d5a-d3aa-5b6e-b4a1-d52b82371bb1
STIX ID: report--448b3d5a-d3aa-5b6e-b4a1-d52b82371bb1
Feed Name: ReversingLabs Blog
Threat Score
ReversingLabs reports that the popular npm package @lottiefiles/lottie-player was compromised when three malicious versions (2.0.5–2.0.7) were published using a hijacked developer token; the altered lottie-player.js displayed web3 wallet connect pop-ups that could enable attackers to drain victims' crypto assets, and ReversingLabs performed differential analysis, flagged behaviors and IOCs, and noted removal and remediation of the malicious releases.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
