Supply chain attack on lottie-player: everything you need to know
ID: 405a8d82-5a04-5dc0-9d15-eaa69bf7e47c
STIX ID: report--405a8d82-5a04-5dc0-9d15-eaa69bf7e47c
Feed Name: Wiz Blog
On 2024-10-30 attackers compromised a maintainer token for the lottie-player npm package and published malicious releases (2.0.5–2.0.7) that inject Web3 wallet connection prompts on sites using the library; compromised packages were later removed from CDNs and npm and a safe version (2.0.8) was released, but sites pinned to affected versions remain at risk. At least one user loss (reported 10 BTC) and impacts to high-traffic sites (e.g., 1inch) were observed; recommended actions are to audit dependencies and update to 2.0.8 or revert to 2.0.4.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
