MIT TRACE

MIT CTL Logo
Back to Main Dashboard

Compromised LottieFiles npm package distributes crypto drainer to downstream websites

On 30 October 2024, an attacker used a phished LottieFiles developer npm account to publish malicious versions 2.0.5, 2.0.6 and 2.0.7 of the legitimate @lottiefiles/lottie-player package. Websites configured to pull the latest package version through public CDNs automatically received the malicious code, which displayed cryptocurrency-wallet prompts. LottieFiles removed the affected versions and published a clean release; Blockaid detected roughly 400 affected websites and reported that additional sites were likely impacted.

70

Estimated severity

70 / 100

92

Source reliability

92 / 100

Approximate Date

30/10/2024

Targeted Company

LOTTIEFILES

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

TOSHIBA (Software vendor)DREAM11 (Software vendor)INGENICO (Software vendor)

Geographic Impact

Country Targeted Company

United States

USA

Other Affected Countries

No other affected countries reported

Target country

United States

Affected countries

No information

Impacted regions

No information

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Supply chain data integrity impact

Affected sectors

Technology & IT Services

Affected departments

Information Technology

Attack Profile

Attack types

Account takeoverPhishingSoftware supply chain compromiseSoftware update compromise

Attributed threat actors

No information

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.