Home / Companies / Snyk / Blog / Post Details
Content Deep Dive

Lottie Player npm package compromised for crypto wallet theft

Blog post from Snyk

Post Details
Company
Date Published
Author
Liran Tal
Word Count
825
Company Posts That Month
20
Language
English
Hacker News Points
2
Post removed?
No
Summary

On October 31st, 2024, the popular npm library @lottiefiles/lottie-player was found to contain malicious code prompting users to connect their crypto wallets. The malicious code was added after an npm registry account token used for publishing packages was compromised. Safe and vulnerable version ranges for Lottie Player npm package are provided, along with instructions on how to use Snyk to determine if you have installed the malicious versions. This incident follows a similar attack vector that impacted the Polyfill library in June 2024, attempting to steal cryptocurrency through a crypto wallet financial theft.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.