Close Menu
  • Latest News
    • Bitcoin
    • Ethereum
    • Altcoins
    • Meme Coins
  • DeFi
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • Gaming
  • Legal
    • Taxes & Regulation
    • Adoption
  • Analysis
  • Learn
    • Education
    • Wallets and Exchanges
  • Tools
    • Market Overview
    • Converter
What's Hot

Trump Media files for Bitcoin and Ethereum ETF

June 17, 2025

Crypto licences divide EU regulators

June 17, 2025

Analyst Sees Ethereum (ETH) Igniting 60% Rally Despite Dip, Says Final Major Resistance for Bitcoin (BTC) Getting Weaker

June 17, 2025
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
Facebook X (Twitter) Instagram
Buy Crypto NewsBuy Crypto News
  • Latest News
    1. Bitcoin
    2. Ethereum
    3. Altcoins
    4. Meme Coins
    5. View All

    Strategy Acquires 10,100 BTC, Surpasses 592,000 Bitcoin In Holdings

    June 17, 2025

    How High/Low Can Bitcoin Price Go This Week?

    June 16, 2025

    Trader Predicts Rallies to New All-Time High for Bitcoin Amid Struggle To Clear $110,000 – But There’s a Big Catch

    June 16, 2025

    Risk of Escalating Israel-Iran Conflict Keeps Bitcoin Around 105K Says QCP

    June 16, 2025

    Analyst Sees Ethereum (ETH) Igniting 60% Rally Despite Dip, Says Final Major Resistance for Bitcoin (BTC) Getting Weaker

    June 17, 2025

    Ethereum recovers 20% in June -Will $3K be ETH’s next stop in Q3?

    June 16, 2025

    Ethereum Weekly Candle Hints At Pre-Tower Top Formation – Details

    June 16, 2025

    Ethereum sees $153mln inflow – But THIS kept ETH price frozen

    June 16, 2025

    Top 11 cloud mining platforms in June 2025

    June 16, 2025

    Chainlink Price Prediction 2025, 2026

    June 16, 2025

    Trader Says One Layer-1 Altcoin ‘Destined’ for New All-Time High, Warns of Potential 50% Correction for WIF and POPCAT

    June 16, 2025

    Ethereum bears lose ground, but ETH bulls may not be safe just yet!

    June 16, 2025

    Pepe, BMT, CAKE: Crypto Activity Heats Up

    March 18, 2025

    SHIB Burns Over Half a Billion Tokens, Price Surges Over 7%

    March 17, 2025

    DOGE Sees Massive User Growth: Active Addresses Up 400%

    March 15, 2025

    Shiba Inu (SHIB) Price Analysis: Bullish Hints, Bearish Trend

    March 15, 2025

    Trump Media files for Bitcoin and Ethereum ETF

    June 17, 2025

    Crypto licences divide EU regulators

    June 17, 2025

    Analyst Sees Ethereum (ETH) Igniting 60% Rally Despite Dip, Says Final Major Resistance for Bitcoin (BTC) Getting Weaker

    June 17, 2025

    Strategy Acquires 10,100 BTC, Surpasses 592,000 Bitcoin In Holdings

    June 17, 2025
  • DeFi

    Bybit launches Solana on-chain CeDeFi app Byreal as DEX volume jumps 16%

    June 16, 2025

    Can ADA escape bearish momentum as a key support zone approaches?

    June 16, 2025

    Tencent reopens talks to acquire South Korea’s Nexon, a game developer exploring blockchain

    June 16, 2025

    HYPE price eyes $50 as Hyperliquid crosses $2b milestone

    June 16, 2025

    Here’s why WhiteBIT’s WBT hit a new all-time high while the crypto market crashed

    June 15, 2025
  • Tech
    1. Blockchain
    2. Security and Privacy
    3. View All

    Crypto licences divide EU regulators

    June 17, 2025

    Orbler Partners with Quizon to Transform Web3 Learning with AI and Gamification

    June 16, 2025

    Coinbase, Gemini Eye EU Expansion With New Licenses: Reuters

    June 16, 2025

    Shiv Srivastava on Ethereum, ZK, and Verifiable Compute

    June 16, 2025

    Threat Actors Target Victims with HijackLoader and DeerStealer

    June 17, 2025

    Coinbase data breach spills offline as victims get scam mail

    June 6, 2025

    Cryptojacking Campaign Targets DevOps Servers Including Nomad

    June 3, 2025

    Sophisticated Malware Campaign Targets Windows and Linux Systems

    June 2, 2025

    Trump Media files for Bitcoin and Ethereum ETF

    June 17, 2025

    Crypto licences divide EU regulators

    June 17, 2025

    Analyst Sees Ethereum (ETH) Igniting 60% Rally Despite Dip, Says Final Major Resistance for Bitcoin (BTC) Getting Weaker

    June 17, 2025

    Strategy Acquires 10,100 BTC, Surpasses 592,000 Bitcoin In Holdings

    June 17, 2025
  • Web 3
    1. Web3 News
    2. Gaming
    3. View All

    CLAPS Unveils Crypto Sportsbook With On-Chain Payments and Instant Fiat Access

    June 17, 2025

    Network Analytics Market Growth, Analysis of Key Players, Trends, Drivers

    June 16, 2025

    VERSE Token and the Rise of Real-World Utility in the Metaverse Economy

    June 16, 2025

    Next Generation Memory Market Size Future Scope, Demands and Projected Industry Growths to 2033

    June 16, 2025

    Games That Feature the Dogecoin Meme Pup

    June 17, 2025

    How Cloud-Based Email Solutions — and Web3 — Can Change Your Business Marketing Efforts

    June 16, 2025

    Dogecoin Got Game, FIFA Rivals Launches

    June 16, 2025

    7 Games That Prove Indie Studios Are Outshining AAA Publishers in 2025

    June 16, 2025

    Trump Media files for Bitcoin and Ethereum ETF

    June 17, 2025

    Crypto licences divide EU regulators

    June 17, 2025

    Analyst Sees Ethereum (ETH) Igniting 60% Rally Despite Dip, Says Final Major Resistance for Bitcoin (BTC) Getting Weaker

    June 17, 2025

    Strategy Acquires 10,100 BTC, Surpasses 592,000 Bitcoin In Holdings

    June 17, 2025
  • Legal
    1. Taxes & Regulation
    2. Adoption
    3. View All

    Stablecoins in Crypto Trading: What Every Trader Should Know

    June 17, 2025

    US prosecutors say Tornado Cash witnesses will ‘waste jury time’

    June 16, 2025

    Vietnam ends crypto ‘Grey Zone’ with sweeping new digital asset legislation

    June 16, 2025

    Former Wex exchange chief to face charges in the U.S.

    June 16, 2025

    Trump Media files for Bitcoin and Ethereum ETF

    June 17, 2025

    Metaplanet’s 10,000 Bitcoin holding trades at $759K each

    June 16, 2025

    Ripple CEO Brad Garlinghouse sees XRP capturing 14% of SWIFT’s market in five years

    June 15, 2025

    XRP’s corporate treasury investments near $1 billion

    June 14, 2025

    Trump Media files for Bitcoin and Ethereum ETF

    June 17, 2025

    Crypto licences divide EU regulators

    June 17, 2025

    Analyst Sees Ethereum (ETH) Igniting 60% Rally Despite Dip, Says Final Major Resistance for Bitcoin (BTC) Getting Weaker

    June 17, 2025

    Strategy Acquires 10,100 BTC, Surpasses 592,000 Bitcoin In Holdings

    June 17, 2025
  • Analysis

    Solana co-founder calls Cardano’s proposed $100M treasury move to Bitcoin ‘so dumb’

    June 16, 2025

    How High Can HYPE Price Go Today?

    June 16, 2025

    Can XRP Price Hit $10?

    June 16, 2025

    Data sovereignty can redefine the global economic markets

    June 15, 2025

    Crypto Strategist Warns of up to 80% Bitcoin Correction in Next Bear Market Fueled by Selling of Major BTC Adoption Group

    June 15, 2025
  • Learn
    1. Education
    2. Wallets and Exchanges
    3. View All

    What Are Internet Capital Markets? Why Companies Are Launching Meme Coins

    June 16, 2025

    What is a Corporate Bitcoin Treasury? The Strategy Behind Companies Holding Crypto

    May 27, 2025

    What Are Tokenized Real-World Assets? Putting Physical Value On-Chain With RWAs

    May 19, 2025

    Users Taunt Grok After xAI Says Modifications Were Made to Spit out ‘White Genocide’ Claim

    May 16, 2025

    Every crypto trade will soon happen inside your wallet

    June 14, 2025

    Coinbase to launch CFTC-cleared perpetual futures trading, Bitcoin-backed credit card for US customers

    June 13, 2025

    FTX continues to exclude Nigeria and China in remaining creditor repayments but includes Payoneer

    June 12, 2025

    BiT Global drops Coinbase lawsuit over wrapped Bitcoin delisting

    June 10, 2025

    Trump Media files for Bitcoin and Ethereum ETF

    June 17, 2025

    Crypto licences divide EU regulators

    June 17, 2025

    Analyst Sees Ethereum (ETH) Igniting 60% Rally Despite Dip, Says Final Major Resistance for Bitcoin (BTC) Getting Weaker

    June 17, 2025

    Strategy Acquires 10,100 BTC, Surpasses 592,000 Bitcoin In Holdings

    June 17, 2025
  • Tools
    • Market Overview
    • Converter
Buy Crypto NewsBuy Crypto News
Home»Security and Privacy»npm Package Lottie-Player Compromised in Supply Chain Attack
npm Package Lottie-Player Compromised in Supply Chain Attack
Security and Privacy

npm Package Lottie-Player Compromised in Supply Chain Attack

November 25, 2024No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A recent supply chain attack on the npm package @lottiefiles/lottie-player has brought to light the vulnerabilities that can arise from software dependencies. This incident, uncovered by ReversingLabs, involved the release of malicious versions of the package earlier this year.

The @lottiefiles/lottie-player package is widely used, with approximately 84,000 weekly downloads. It is utilized to embed and play Lottie animations on websites. However, malicious actors were able to compromise the package by releasing unauthorized versions – 2.0.5, 2.0.6, and 2.0.7 – via a privileged developer account. These malicious updates contained altered code that prompted users to connect their web3 wallets, allowing attackers to access and drain victims’ crypto wallet assets.

Fortunately, developers quickly noticed unusual behaviors on affected sites and raised the alarm, leading to discussions on forums and GitHub. LottieFiles responded promptly by working with npm to remove the malicious versions and release a clean version based on the last secure release – version 2.0.4. Automatic updates were provided to developers using the @latest dependency configuration, helping to mitigate potential impacts.

ReversingLabs researchers played a crucial role in detecting the compromise by conducting a differential analysis between the secure version 2.0.4 and the malicious version 2.0.7. This analysis revealed significant changes, such as an increased file size without justification, introduction of URLs linked to Bitcoin exchanges, and the removal of standard behaviors like display enumeration. Threat-hunting policies were also employed to detect patterns resembling known software supply chain attacks.

This incident serves as a reminder to developers about the importance of pinning dependencies to specific, vetted versions to prevent vulnerabilities in auto-updated packages. Regular security assessments of dependencies and build pipelines are essential to identify potential risks. ReversingLabs emphasized the need for developers to conduct thorough security assessments to verify the integrity and quality of public, open-source libraries before integrating them into their projects.

See also  HashKey Chain Partners with OKX Web3 Wallet to Boost User Rewards and Experience

In conclusion, while the @lottiefiles/lottie-player supply chain compromise was swiftly addressed, developers must remain vigilant and proactive in safeguarding their software supply chain against potential threats. Stay informed, stay secure.

Attack Chain Compromised LottiePlayer npm Package Supply
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Threat Actors Target Victims with HijackLoader and DeerStealer

June 17, 2025

$1.14 Billion Wiped Out as Market Faces Double Attack? 

June 15, 2025

Has Ethereum’s bullish breakout hit a roadblock at the supply zone?

June 12, 2025

World Chain and Circle join forces to strengthen identity-driven finance with native USDC

June 12, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Bitcoin Price Prediction Today (12th Dec 2024)!

December 12, 2024

Bitcoin Nears All-Time Highs, But Retail Interest Still Remains Low

May 23, 2025

Phantom App: A Complete Guide to the Phantom Wallet App for NFTs and Blockchain Gaming

April 13, 2025
Price Chart


Explore insights on crypto, blockchain, taxes, and security. Stay informed with expert guides, tips, and the latest trends to navigate the digital asset world confidently


We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Trump Media files for Bitcoin and Ethereum ETF

June 17, 2025

Crypto licences divide EU regulators

June 17, 2025

Analyst Sees Ethereum (ETH) Igniting 60% Rally Despite Dip, Says Final Major Resistance for Bitcoin (BTC) Getting Weaker

June 17, 2025
Get Informed

Subscribe to Updates

Get the latest creative news From BuyCryptoNews directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclosure
© 2025 BuyCryptoNews - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.