Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • DeFi
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • Gaming
  • Legal
    • Taxes & Regulation
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Converter
What's Hot

Bluebird gold mining company embraces Bitcoin in bold shift from tradition, shares soar 60%

June 5, 2025

Moonchain price surges 70%, eyes uptrend continuation after key level reclaim

June 5, 2025

JPMorgan Plans to Let Clients Borrow Against Crypto ETFs – Here’s What That Means

June 5, 2025
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Buy Crypto NewsBuy Crypto News
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    Bitcoin Setting Up for ‘Treasonous’ Correction, According to Trader That Called 2021 Market Cycle

    June 5, 2025

    Vitalik’s Plan Can Bring ETH to $3,000 and Crypto (XRP, BTC) ‘More Popular’ Than Stocks in Korea

    June 5, 2025

    JPMorgan To Offer Clients Financing Against Bitcoin & Crypto ETFs

    June 5, 2025

    Bitcoin Price Prediction Today: 4th June

    June 4, 2025

    Top Reasons Why Ethereum Price Rally is on the Cards

    June 5, 2025

    Ethereum Consolidates Against BTC – Altseason Hopes Hinge On ETH/BTC Breakout

    June 5, 2025

    Ethereum: Whales now hold $365mln in ETH – Is a run to $3.4K loading?

    June 5, 2025

    Ethereum Price on the Edge: Vitalik, Whales, and Analysts Hint at a Breakout?

    June 5, 2025

    Ethereum Foundation’s treasury plan – Will a 66% spending cut boost ETH’s value?

    June 5, 2025

    XRP Lawsuit End When? Expert Says SEC Dropped Appeal, 60-Day Delay Could Follow Ripple

    June 5, 2025

    Stablecoin Issuer Circle Targeting $7,200,000,000 Valuation in Upcoming IPO

    June 5, 2025

    Is an XRP ETF approval closer than ever? 93% Polymarket rating suggests…

    June 4, 2025

    Pepe, BMT, CAKE: Crypto Activity Heats Up

    March 18, 2025

    SHIB Burns Over Half a Billion Tokens, Price Surges Over 7%

    March 17, 2025

    DOGE Sees Massive User Growth: Active Addresses Up 400%

    March 15, 2025

    Shiba Inu (SHIB) Price Analysis: Bullish Hints, Bearish Trend

    March 15, 2025

    Bluebird gold mining company embraces Bitcoin in bold shift from tradition, shares soar 60%

    June 5, 2025

    Moonchain price surges 70%, eyes uptrend continuation after key level reclaim

    June 5, 2025

    JPMorgan Plans to Let Clients Borrow Against Crypto ETFs – Here’s What That Means

    June 5, 2025

    Top Reasons Why Ethereum Price Rally is on the Cards

    June 5, 2025
  • DeFi

    Moonchain price surges 70%, eyes uptrend continuation after key level reclaim

    June 5, 2025

    Reddit sues AI firm Anthropic over unauthorised data scraping for Claude

    June 5, 2025

    Systemic risk on the rise as leverage interdependencies tighten between CeFi, DeFi and crypto treasuries

    June 5, 2025

    COTI launches PriveX, a privacy-first platform for perp trading

    June 5, 2025

    Sui rallies past $1.75B TVL as bitcoin and stablecoin flows spike

    June 4, 2025
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    JPMorgan Plans to Let Clients Borrow Against Crypto ETFs – Here’s What That Means

    June 5, 2025

    NEAR Intents Makes Cross-Chain BNB Swaps A Total Breeze

    June 5, 2025

    Circle Upsizes NYSE IPO to $1.05B — Here’s What Investors Should Watch

    June 5, 2025

    Mogul Club, Ava Labs partner to bring tokenized real estate to web3 investors

    June 5, 2025

    Cryptojacking Campaign Targets DevOps Servers Including Nomad

    June 3, 2025

    Sophisticated Malware Campaign Targets Windows and Linux Systems

    June 2, 2025

    US Treasury sanctions Philippines tech firm over aiding $200 million pig butchering spree

    May 31, 2025

    Fake Bitdefender Site Spreads Trio of Malware Tools

    May 28, 2025

    Bluebird gold mining company embraces Bitcoin in bold shift from tradition, shares soar 60%

    June 5, 2025

    Moonchain price surges 70%, eyes uptrend continuation after key level reclaim

    June 5, 2025

    JPMorgan Plans to Let Clients Borrow Against Crypto ETFs – Here’s What That Means

    June 5, 2025

    Top Reasons Why Ethereum Price Rally is on the Cards

    June 5, 2025
  • Web 3
    1. Web3 News
    2. Gaming
    3. View All

    Iran-aligned BladedFeline spies on Iraqi and Kurdish officials, ESET Research discovers

    June 5, 2025

    SPEC Resumes Global Collaboration with Companies on U.S. BIS Entity List

    June 5, 2025

    Notification of transactions in Columbus A/S shares and related securities by persons discharging managerial responsibilities and persons closely associated with them

    June 5, 2025

    How to earn a steady income every day, remotely start a Bitcoin mining machine with XRP using your phone or computer.

    June 4, 2025

    The Flappy Bird Crypto Game That’s Paying Out More Than You Think

    June 5, 2025

    ‘Flappy Bird’ Is Making a Crypto Gaming Push After All

    June 5, 2025

    Vi Powils Named CEO of World of Women as Project Enters New Growth Phase

    June 4, 2025

    Magic Eden’s “Official Trump Wallet” Backfires After Trump Family Disavows Project

    June 4, 2025

    Bluebird gold mining company embraces Bitcoin in bold shift from tradition, shares soar 60%

    June 5, 2025

    Moonchain price surges 70%, eyes uptrend continuation after key level reclaim

    June 5, 2025

    JPMorgan Plans to Let Clients Borrow Against Crypto ETFs – Here’s What That Means

    June 5, 2025

    Top Reasons Why Ethereum Price Rally is on the Cards

    June 5, 2025
  • Legal
    1. Taxes & Regulation
    2. Adoption
    3. View All

    US takes down 145 domains linked to $17M darknet marketplace and seize crypto wallets

    June 5, 2025

    Here’s What’s at Stake for Crypto in South Korea’s Upcoming Election

    June 5, 2025

    Moroccan police arrests suspect behind recent crypto-related kidnappings in France

    June 5, 2025

    Binance Breaks Silence After SEC Lawsuit Dismissal: Details

    June 5, 2025

    Bluebird gold mining company embraces Bitcoin in bold shift from tradition, shares soar 60%

    June 5, 2025

    Sentient’s AI chatbot Dobby Plus challenges OpenAI with open-source, user-governed AI model

    June 5, 2025

    Circle set to exceed IPO expectations after overwhelming investor demand

    June 5, 2025

    JPMorgan to accept Bitcoin ETFs as loan collateral, consider digital holdings in evaluations

    June 5, 2025

    Bluebird gold mining company embraces Bitcoin in bold shift from tradition, shares soar 60%

    June 5, 2025

    Moonchain price surges 70%, eyes uptrend continuation after key level reclaim

    June 5, 2025

    JPMorgan Plans to Let Clients Borrow Against Crypto ETFs – Here’s What That Means

    June 5, 2025

    Top Reasons Why Ethereum Price Rally is on the Cards

    June 5, 2025
  • Analysis

    Kaspa coin price prediction 2025

    June 5, 2025

    Analyst Says Solana-Based Memecoin Setting Stage for ‘Full-Blown Parabola,’ Predicts New All-Time High for One Asset

    June 5, 2025

    XRPL faces scam influx amid institutional interest boom

    June 4, 2025

    Ethereum and XRP steals spotlight in daily gains after Bitcoin reclaimed $106k

    June 4, 2025

    XRP Price Prediction for June 4, 2025 

    June 4, 2025
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What is a Corporate Bitcoin Treasury? The Strategy Behind Companies Holding Crypto

    May 27, 2025

    What Are Tokenized Real-World Assets? Putting Physical Value On-Chain With RWAs

    May 19, 2025

    Users Taunt Grok After xAI Says Modifications Were Made to Spit out ‘White Genocide’ Claim

    May 16, 2025

    What Is Base? The Ethereum Layer-2 Network Launched by Coinbase

    April 29, 2025

    NGX becomes first public Norwegian firm to adopt the Bitcoin standard, stock surges 138%

    June 5, 2025

    Trump family denies involvement in new wallet launch

    June 4, 2025

    Tether invests in Orionx to boost stablecoin use in Latin America

    June 4, 2025

    Bitstamp finally folds into Robinhood in $200M merger, unlocking global crypto passport

    June 3, 2025

    Bluebird gold mining company embraces Bitcoin in bold shift from tradition, shares soar 60%

    June 5, 2025

    Moonchain price surges 70%, eyes uptrend continuation after key level reclaim

    June 5, 2025

    JPMorgan Plans to Let Clients Borrow Against Crypto ETFs – Here’s What That Means

    June 5, 2025

    Top Reasons Why Ethereum Price Rally is on the Cards

    June 5, 2025
  • Tools
    • Market Overview
    • Converter
Buy Crypto NewsBuy Crypto News
Home»Security and Privacy»npm Package Lottie-Player Compromised in Supply Chain Attack
npm Package Lottie-Player Compromised in Supply Chain Attack
Security and Privacy

npm Package Lottie-Player Compromised in Supply Chain Attack

November 25, 2024No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A recent supply chain attack on the npm package @lottiefiles/lottie-player has brought to light the vulnerabilities that can arise from software dependencies. This incident, uncovered by ReversingLabs, involved the release of malicious versions of the package earlier this year.

The @lottiefiles/lottie-player package is widely used, with approximately 84,000 weekly downloads. It is utilized to embed and play Lottie animations on websites. However, malicious actors were able to compromise the package by releasing unauthorized versions – 2.0.5, 2.0.6, and 2.0.7 – via a privileged developer account. These malicious updates contained altered code that prompted users to connect their web3 wallets, allowing attackers to access and drain victims’ crypto wallet assets.

Fortunately, developers quickly noticed unusual behaviors on affected sites and raised the alarm, leading to discussions on forums and GitHub. LottieFiles responded promptly by working with npm to remove the malicious versions and release a clean version based on the last secure release – version 2.0.4. Automatic updates were provided to developers using the @latest dependency configuration, helping to mitigate potential impacts.

ReversingLabs researchers played a crucial role in detecting the compromise by conducting a differential analysis between the secure version 2.0.4 and the malicious version 2.0.7. This analysis revealed significant changes, such as an increased file size without justification, introduction of URLs linked to Bitcoin exchanges, and the removal of standard behaviors like display enumeration. Threat-hunting policies were also employed to detect patterns resembling known software supply chain attacks.

This incident serves as a reminder to developers about the importance of pinning dependencies to specific, vetted versions to prevent vulnerabilities in auto-updated packages. Regular security assessments of dependencies and build pipelines are essential to identify potential risks. ReversingLabs emphasized the need for developers to conduct thorough security assessments to verify the integrity and quality of public, open-source libraries before integrating them into their projects.

See also  Crypto Romance Scam Drains $1.4M

In conclusion, while the @lottiefiles/lottie-player supply chain compromise was swiftly addressed, developers must remain vigilant and proactive in safeguarding their software supply chain against potential threats. Stay informed, stay secure.

Attack Chain Compromised LottiePlayer npm Package Supply
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

BNB Chain Launches AI Bot to Help Devs and Block Scammers

June 3, 2025

Cryptojacking Campaign Targets DevOps Servers Including Nomad

June 3, 2025

Sophisticated Malware Campaign Targets Windows and Linux Systems

June 2, 2025

470M XRP locked away – Why Ripple’s latest supply squeeze won’t be enough!

June 2, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

XRP fails to clear $2.50 resistance – Are bears poised to take over?

March 28, 2025

North Korea Spies Used Fake US Firms to Hack Crypto Developers: Report

April 25, 2025

SOL Strategies Locks In Record $500M Note to Turbo-Charge SOL Staking Yield

April 24, 2025
Price Chart


Explore insights on crypto, blockchain, taxes, and security. Stay informed with expert guides, tips, and the latest trends to navigate the digital asset world confidently


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Bluebird gold mining company embraces Bitcoin in bold shift from tradition, shares soar 60%

June 5, 2025

Moonchain price surges 70%, eyes uptrend continuation after key level reclaim

June 5, 2025

JPMorgan Plans to Let Clients Borrow Against Crypto ETFs – Here’s What That Means

June 5, 2025
Get Informed

Subscribe to Updates

Get the latest creative news From BuyCryptoNews directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2025 BuyCryptoNews - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.