logo

Supply chain attack on lottie-player: everything you need to know

ID: 405a8d82-5a04-5dc0-9d15-eaa69bf7e47c

STIX ID: report--405a8d82-5a04-5dc0-9d15-eaa69bf7e47c

Feed Name: Wiz Blog

Threat Score
85/100

Date Published: 2024-10-31

Date Updated: 2026-05-01

...
...

On 2024-10-30 attackers compromised a maintainer token for the lottie-player npm package and published malicious releases (2.0.5–2.0.7) that inject Web3 wallet connection prompts on sites using the library; compromised packages were later removed from CDNs and npm and a safe version (2.0.8) was released, but sites pinned to affected versions remain at risk. At least one user loss (reported 10 BTC) and impacts to high-traffic sites (e.g., 1inch) were observed; recommended actions are to audit dependencies and update to 2.0.8 or revert to 2.0.4.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.