Supply Chain Attack on LottieFiles Player Caused by Compromi...
Blog post from Socket
A supply chain attack targeted the LottieFiles Player npm package after a software engineer's npmjs credentials were compromised, allowing a threat actor to inject malicious code into versions 2.0.5, 2.0.6, and 2.0.7. This malicious code caused a crypto wallet popup to appear on legitimate websites using the affected versions. LottieFiles, a platform for motion graphics, responded swiftly by removing compromised account access and releasing version 2.0.8, which reverted to the last clean version 2.0.4. npm quickly removed the malicious versions, but they are still available on CDNjs.com via explicit version specifiers. Despite Socket's AI scanner flagging the package as a supply chain risk, it initially failed to identify the improper context of the crypto-related code. LottieFiles is still investigating the incident, and it remains unclear how the threat actor bypassed security measures, such as two-factor authentication. The company advises developers to pin package versions and use tools like Socket for GitHub to assess new versions for risks before deployment.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.