United States
USA
On 30 October 2024, an attacker used a phished LottieFiles developer npm account to publish malicious versions 2.0.5, 2.0.6 and 2.0.7 of the legitimate @lottiefiles/lottie-player package. Websites configured to pull the latest package version through public CDNs automatically received the malicious code, which displayed cryptocurrency-wallet prompts. LottieFiles removed the affected versions and published a clean release; Blockaid detected roughly 400 affected websites and reported that additional sites were likely impacted.
Estimated severity
70 / 100
Source reliability
92 / 100
Approximate Date
30/10/2024
Targeted Company
LOTTIEFILES
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
United States
USA
No other affected countries reported
Target country
United States
Affected countries
No information
Impacted regions
No information
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
No information
Incident Sources
Please rotate your phone