All vulnerabilities
CRITICALSupply chainexploited in the wild

NPM-LOTTIE-PLAYER-2024

npm · @lottiefiles/lottie-player

Summary

On October 31, 2024, LottieFiles disclosed that an employee's npm account was compromised via phishing and used to publish malicious versions 2.0.5, 2.0.6 and 2.0.7 of @lottiefiles/lottie-player. The injected code embedded a crypto wallet drainer that prompted website visitors to connect their wallets, then attempted to siphon funds. Sites loading the library from unpinned CDN versions were automatically served the malicious update; one victim reportedly lost about $723,000 in Bitcoin. A clean version 2.0.8 matching 2.0.4 was released in response.

References

Related vulnerabilities

All Supply chain →