As cited
Copy frozen at (site build).
breaches incidents
Supply chain attack on lottie-player: everything you need to know
A supply chain attack compromised the lottie-player library, a popular tool used in web development. The compromised versions inject malicious Web3 wallet prompts into affected websites. Users should update to a patched version or revert to an earlier uncompromised release.
Why it matters: Developers and web administrators using lottie-player need to audit and patch immediately to prevent their sites from displaying credential-harvesting prompts to users.
- Source published
- First seen by Cybersecurity Tracker