logo

Differential analysis raises red flags over @lottiefiles/lottie-player

ID: 448b3d5a-d3aa-5b6e-b4a1-d52b82371bb1

STIX ID: report--448b3d5a-d3aa-5b6e-b4a1-d52b82371bb1

Feed Name: ReversingLabs Blog

Threat Score
82/100

Date Published: 2024-11-21

Date Updated: 2026-04-29

Author: [email protected] (Lucija Valentić)

...
...

ReversingLabs reports that the popular npm package @lottiefiles/lottie-player was compromised when three malicious versions (2.0.5–2.0.7) were published using a hijacked developer token; the altered lottie-player.js displayed web3 wallet connect pop-ups that could enable attackers to drain victims' crypto assets, and ReversingLabs performed differential analysis, flagged behaviors and IOCs, and noted removal and remediation of the malicious releases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.